Guide
How Quaso works
A tour of the building blocks: connections, triggers, the browser, file processing, and the advanced bits that let your agents run real production workloads.
Overview
Quaso is an AI agent that connects to your tools and gets work done on your behalf. Instead of just answering questions like a chatbot, Quaso actually takes action: it sends emails, updates spreadsheets, files tickets, posts to Slack, and a lot more.
You interact with Quaso through conversation. Describe what you need, and it will ask any clarifying questions it needs, hook up the relevant services, and execute. You can also set triggers so it runs automatically on a schedule, when a specific email arrives, or when another event fires.
Quaso integrates with thousands of apps out of the box, and you can point it at any HTTP API directly if a built-in integration is missing. It also has its own cloud sandbox where it can run code, process files, and (thanks to our partnership with Notte) drive a real browser to interact with software that has no API. Because it reasons step by step, it can handle edge cases that would break a rigid automation tool.
Quaso is built for founders, operators, and professionals who want to automate real work, especially the kind of business processes that need to run reliably around the clock: support triage, lead routing, reporting, ops workflows.
Connections
Connections are how Quaso reaches your apps. There are over 3,000 built-in integrations, plus the ability to call any HTTP API or MCP server. If a service doesn't have an API at all, Quaso can still use it through the browser. Just say something like "Connect my Gmail" to get started.
How connections work
- You authorize access. Quaso opens a secure login flow and you sign in directly with the service.
- You choose what to grant.Each connection unlocks specific tools (e.g. "send email", "create ticket"). Quaso asks before activating anything new.
- The tools become available. From there on Quaso can use them to complete work for you.
Custom APIs & MCP servers
Quaso connects to any HTTP API or MCP server. Register a custom Streamable-HTTP MCP server (like Supabase) under Settings โ MCP servers: paste its URL, add a bearer token or header if it needs one, and hit Test connection to see the tools it exposes. From then on the agent can call those tools in chat. Tokens are encrypted at rest and never shown to the model. Works with public APIs and your own internal services too.
Security
- Credentials are encrypted at rest; Quaso never sees your password.
- OAuth is used wherever the service supports it.
- You can revoke access at any time from Settings โ Connections.
- After approving an app, you control exactly which tools Quaso can use. Read-only is fine when that's all you want.
Triggers
Triggers let Quaso run automatically. On a schedule, when an email arrives, when a calendar event changes, or when another service sends an event - anything you can describe.
How to create one
Describe what you want and when. Examples that work right away:
- "Send me a daily briefing every morning at 9am."
- "When I get an email with an attachment, file it in Drive."
- "Every Friday, post a recap of closed deals to #sales."
What you can trigger on
Schedule (daily, weekly, custom schedule), external events (another system sending data to a URL Quaso gives you), RSS feeds, Gmail (new mail or label applied), Google Calendar (event created, changed, starting), Google Drive (file or folder change), Notion (page or database updates), HubSpot (CRM changes), GitHub (PRs, issues, pushes), text messages and email replies for talking to your agents on the go.
Multiple triggers per agent
One agent can hold several triggers. An inbox assistant might run a daily briefing, draft replies on new mail, and star important messages, all from the same agent definition.
Text & Email Messaging
Quaso can send and receive messages over email or text (iMessage and RCS). When someone replies, the agent picks it up and can keep the conversation going or take action on the response.
Email anyone (with permission)
You can add any email address as a contact. The recipient confirms via a one-click verification link, and after that your agent can send them reports, notifications, or approval requests directly.
Two-way conversations
Replies to Quaso's messages land back in the agent. The recipient doesn't need their own Quaso account: they just reply like they would to any other email or text.
Setting it up
- Ask your agent to add a contact method.
- The recipient verifies (link for email, text reply for phone).
- Your agent can message them from then on.
File Processing
Quaso can shuttle files between connections (Gmail, Drive, Slack, APIs), process them, and create new ones from scratch.
What it can do
- Transfer attachments and downloads between services.
- Convert images, audio, documents into different formats.
- Create spreadsheets, PDF reports, even videos with narration.
- Edit images and clean up data files.
- Merge & split PDFs and large files.
- Analyze long CSVs and produce summary stats and charts.
Combine with triggers
File processing pairs naturally with triggers. Pull data from your CRM every morning and generate a summary PDF. Save every receipt that lands in your inbox into a Drive folder and log it in a spreadsheet. Watch a public dataset and alert if anything moves.
Browser
Every Quaso agent has a built-in browser, powered by Notte. That means it can navigate authenticated sites, fill forms, click through multi-step flows, and pull data from pages that don't expose an API. This is what makes Quaso's automation surface essentially endless.
How to use it
Describe what you need. Quaso will open a browser if that's the best tool for the job. You can also say "use the browser to..." if you want to be explicit, though usually it's smarter to let the agent pick: built-in integrations are often faster, cheaper, and more reliable when they exist.
What it can do
- Navigate complex pages, type, click, scroll dynamic content.
- Fill forms and walk multi-step flows.
- Extract data from tables, lists, article bodies.
- Upload and download files.
- Hand off sign-in or CAPTCHA to you when a site demands it.
Logins and CAPTCHAs
Quaso never asks for your password. When a site needs you to sign in or solve a challenge, the agent surfaces a live browser preview right in the conversation. You take over, type your credentials or solve the CAPTCHA, hand control back, and the agent resumes.
Persistent sessions
Each agent keeps its own browser profile. Once you've signed in through a preview, the agent stays signed in for future tasks. Cookies, preferences, and any data the site stored carry over the same way.
Use cases
Things people actually run
Real workflows Quaso handles across teams. Click any card to open it in the composer, edit to taste, and hit send.
Comms
Operations
Admin
Growth
Insights
Security
How we keep your data safe
Quaso is built by the team behind Notte, the browser infrastructure company powering AI agents at production scale. Quaso runs on the exact same stack: same browser fleet, same isolation guarantees, same security posture. You get a product surface built for end users, on infrastructure already vetted by enterprise teams running browser agents in production.
SOC 2 compliant
We follow SOC 2 controls across security, availability, and confidentiality. Every control, our auditor reports, sub-processor list, and policy documents live on our public trust portal: trust.notte.cc. Request access there to download the latest report under NDA.
Isolated execution
Every Quaso agent runs in its own sandboxed environment. Browser sessions, code execution, and any virtual machines we spin up for an agent are fully isolated from other workspaces. Your data, code, and credentials never cross tenant boundaries.
Your data is yours
- We do not sell customer data, ever.
- Your conversations and outputs are never used to train third-party AI models.
- Credentials you share for direct API connections are stored in an encrypted vault with strict access controls. Quaso never sees plaintext passwords for OAuth integrations: the service you connect to handles auth directly.
- Internal access to customer data is gated by our admin tooling and requires explicit customer approval. Nobody on the team browses workspaces uninvited.
Encryption
Data is encrypted at rest with AES-256 and in transit with TLS 1.2+. Secrets and integration tokens get an additional layer of envelope encryption inside the credential vault.
Sub-processors
We keep the list short and intentional. The full, always-current roster lives on trust.notte.cc. High-level: Anthropic and OpenAI for model inference, Supabase for the application database, Vercel for hosting the web app, Notte for browser infrastructure, and Stripe for billing.
Vulnerability disclosure
If you find a security issue, please email security@notte.cc instead of disclosing publicly. We will acknowledge within one business day, work in good faith to fix it, and keep you in the loop. We do not pursue researchers acting in good faith under a reasonable disclosure policy, and we may extend a bounty for high-impact reports at our discretion.
Deleting your data
You can delete your workspace at any time from settings. That wipes your conversations, threads, agent files, browser session state, and integration credentials. Retention for backups follows the schedule documented on the trust portal.
Legal
Full agreements: Terms of Use and Privacy Policy.