QualChat brings approvals, support, CRM and ERP into the conversation — cards you can click, act on, and audit. One system across Web, Windows, macOS and Android. Your data always stays yours; you decide how to deploy.
Below is a faithful recreation of the real product: 7 everyday business scenarios. Click the buttons on the cards and watch statuses update in place, confirmations leave an audit trail, linked cards close together, and claim times get measured.
Not sell-first-use-later — our own company runs on this system every day. Every number below comes from our production environment.
In ordinary IM, messages are read and scrolled past. QualChat cards give every task a result, a record, and an owner.
Chat, email, to-dos, knowledge base, files… no more bouncing between six apps.
Every safeguard lives in the architecture and the process — never in someone "being careful".
The uploads directory is a ZFS bind mount from a separate storage pool — deploys structurally cannot delete user data. Production is released manually only; every release is tagged and rollback-able.
Ed25519-signed licensing, no phone-home, no callbacks — it works fully offline. Even if a license expires, only add-on modules pause; basic chat never stops. Even if the vendor vanished tomorrow, your system keeps running.
Channel secrets are stored AES-256-GCM encrypted; form attachments are gated by a separate authorization table — even "knowing the file id + holding a key" can't exfiltrate someone else's attachment; the file's very existence is never revealed.
Every database migration is re-runnable and recorded in a ledger table; CI validates each migration SQL against a throwaway PostgreSQL; when pending migrations exist, deploys back up first, then migrate.
Multi-site sync runs over HMAC-signed channels, fully isolated from user tokens; the four-stage attachment pipeline verifies sha256 and rebuilds automatically from scratch on mismatch.
Card forms: 5-second submit dedup blocks double clicks; the server enforces submitter, deadline and policy checks against privilege abuse; attachment authorization lookups block bulk exfiltration.
Public-internet logins require two-step verification (codes delivered via DingTalk work notifications), with automatic lockout after repeated failures; trusted devices skip the second step and can be revoked anytime; admins can revoke all sessions of any employee in one click.
The control plane only manages tenant placement and never touches a single message; cross-company channels require mutual approval by both admins; external mirror users can't create groups or DM anyone — the boundaries are baked into the protocol.
Login attempts, admin operations and open-API calls are all logged: who, when, from which IP, did what — security incidents can be reconstructed end to end.
Zero-friction trial; when you convert, your data doesn't move.
Leave your name and phone number below and we'll contact you the same day to open your trial — sign up and go, no servers to prepare, no IT involvement. The trial environment comes pre-seeded with demo data: colleagues, message history, to-do cards and more, so you land on a working workspace instead of an empty shell.
Create groups, connect channels, turn one of your approval/notification flows into cards — our engineers work with you until your first business scenario runs end to end, instead of handing you a doc.
After acceptance we deliver formally: deployed in your data center or cloud, or a dedicated instance managed by us. Lightweight architecture (single binary + PostgreSQL); your data always stays yours, and switching deployment models later is painless.
Take the in-page tour · Add us on WeCom for a trial account · Book a 30-minute demo and let's talk through your scenarios