Security & Trust

Private by design. Explicit by operation.

Client environments are governed by explicit tenancy, identity, audit and recovery controls. This page states the product position. Due diligence receives the evidence.

Control model

Fixed product boundaries. Client-specific confirmation.

Some controls are properties of the product; others depend on the deployment. Both columns are answered in writing during operational due diligence.

Control area Product position Confirmed during due diligence
Tenant boundary

Dedicated single-tenant environments for OneBook and private deployments. Plan-based API access is scoped per identity and per tenant.

Cloud account, network boundary and approved region.

Identity & access

Explicit users, roles, service identities and agent scopes. Least-privilege by default; no shared credentials.

SSO / OIDC / SAML path, MFA policy and joiner-mover-leaver process.

Encryption & secrets

Encrypted transport and storage. Vendor credentials and keys live in a managed secrets vault - never in code, configuration or the client browser.

Approved standards, key ownership and secrets-management model.

Audit & lineage

User, service and agent actions are traceable. API responses carry request lineage; decision records retain source snapshots.

Retention period, export destination and monitoring integration.

Backups & recovery

Recoverable application and decision history with defined restore paths.

Frequency, retention, RPO, RTO and recovery-test cadence.

Vulnerability management

Dependency, image and infrastructure controls in the release pipeline.

Scanning cadence, remediation targets and current assurance status.

Incident response

Defined ownership, escalation and evidence preservation.

Support hours, contacts and notification targets.

Data residency

EU-region cloud infrastructure by default; the region is fixed per deployment.

Region, subprocessor list and transfer mechanism.

QuantJourney does not publish a certification, penetration-test status, RPO, RTO or incident SLA unless it is current, evidenced and applicable to the proposed deployment.