[ for enterprise ]

Documentation infrastructure your security team can sign off on.

Quill ships with the controls procurement asks about: SSO, SCIM, audit trails, role-based access, configurable retention, and a self-hosted option that never leaves your VPC. Built so security review is a checkbox, not a six-month project.

[ compliance & trust ]

The controls your buyer's procurement team is going to ask about.

We publish our security posture so you don't have to chase us for a SOC 2 report mid-deal. Detailed responses on request — most teams finish review without a call.

soc 2
Type II
audited annually
iso 27001
in progress
target Q4
gdpr
DPA on file
EU sub-processor list
hipaa
BAA available
on enterprise plans
[ identity & access ]

Sign in the way the rest of your stack already does.

SAML SSO

Bring your IdP — Okta, Azure AD, Google, OneLogin, JumpCloud, anything SAML 2.0. Configurable session lifetimes, enforced re-auth on sensitive actions, just-in-time provisioning.

SCIM provisioning

User and group sync from your directory. Onboarding and offboarding happen the same way they happen for every other tool. No orphaned accounts, no shared credentials.

Role-based access

Per-workspace, per-document, per-action roles. Reviewers, publishers, viewers, admins. Optional approval chains for regulated environments.

[ self-hosted ]

Run Quill inside your perimeter.

For teams whose code can't touch a vendor cloud — finance, healthcare, defense, regulated SaaS. Quill ships as a container that runs in your VPC and reads repos from your existing source control. Data stays where your data already is.

Your infrastructure, your data

Deploy on Kubernetes, ECS, or a single VM. Repository contents, generated articles, screenshots, audio, and audit logs — all persisted in storage you control. Quill phones home only for license verification (and that's offline-friendly too).

BYO LLM

Point Quill at your existing Anthropic, OpenAI, or Bedrock deployment. No model calls leave your AWS account. Self-hosted Llama variants supported for fully air-gapped environments.

Encryption everywhere

TLS in transit, AES-256 at rest, customer-managed KMS keys for workspaces that need them. Per-tenant key rotation supported.

Audit trails

Every action — pipeline runs, document edits, role changes, publishes — written to a structured audit log. Streamable to Splunk, Datadog, or your SIEM of choice. Configurable retention up to 7 years.

[ why enterprise teams choose quill ]

We've been outsourcing technical writing for fifteen years. Quill is the first tool that produces documentation we'd accept from a senior contractor — and the only one that catches it when our APIs drift.

— platform engineering lead, Fortune 500 SaaS
[ built for scale ]

Multi-repo, multi-team, multi-region.

Monorepos & microservices

Per-service docs that link across boundaries. Quill understands workspace scopes, service-to-service contracts, and which team owns which surface.

Approval workflows

Multi-stage review chains: tech lead → docs lead → legal for public surfaces. Skip stages for internal pages. Optional required reviewers per document tree.

Region pinning

Data residency in US, EU, or APAC. Per-workspace region pinning for orgs with cross-border data restrictions.

Talk to our team about a pilot.

We'll walk you through the security posture, scope a proof-of-concept against your codebase, and put you on a procurement track that finishes this quarter.