Security & Trust
Private by design. Explicit by operation.
Client environments are governed by explicit tenancy, identity, audit and recovery controls. This page states the product position. Due diligence receives the evidence.
Control model
Fixed product boundaries. Client-specific confirmation.
Some controls are properties of the product; others depend on the deployment. Both columns are answered in writing during operational due diligence.
Dedicated single-tenant environments for OneBook and private deployments. Plan-based API access is scoped per identity and per tenant.
Cloud account, network boundary and approved region.
Explicit users, roles, service identities and agent scopes. Least-privilege by default; no shared credentials.
SSO / OIDC / SAML path, MFA policy and joiner-mover-leaver process.
Encrypted transport and storage. Vendor credentials and keys live in a managed secrets vault - never in code, configuration or the client browser.
Approved standards, key ownership and secrets-management model.
User, service and agent actions are traceable. API responses carry request lineage; decision records retain source snapshots.
Retention period, export destination and monitoring integration.
Recoverable application and decision history with defined restore paths.
Frequency, retention, RPO, RTO and recovery-test cadence.
Dependency, image and infrastructure controls in the release pipeline.
Scanning cadence, remediation targets and current assurance status.
Defined ownership, escalation and evidence preservation.
Support hours, contacts and notification targets.
EU-region cloud infrastructure by default; the region is fixed per deployment.
Region, subprocessor list and transfer mechanism.
QuantJourney does not publish a certification, penetration-test status, RPO, RTO or incident SLA unless it is current, evidenced and applicable to the proposed deployment.