Human approval
Capital authority remains gated by review, entitlement, and approval state.
Quantitative products, agents, platforms, and Connect APIs are open for approved institutional partners.
Trust center
QSentia connects model intelligence to capital only through guarded access, human review, evidence records, and operational controls.
Trust posture
TLS
Encrypted traffic
RLS
Supabase data controls
Hashed
API key storage
Q4 2026
SOC 2 Type I target
Institutional guardrails
The trust model is intentionally practical: protect access, preserve evidence, separate review from authority, and make control status visible instead of implied.
Capital authority remains gated by review, entitlement, and approval state.
Signals, portfolio context, risk decisions, approvals, and outcomes stay attached to the record.
Authentication, server-side credentials, scoped keys, and route controls keep private workflows protected.
Control status
Implemented controls, active work, and planned validation are separated so institutional partners can review the platform honestly.
Transport + storage
How QSentia protects sessions, browser traffic, and persisted production data.
All client traffic is encrypted over HTTPS, with no plain HTTP application fallback.
Production Supabase data is encrypted at rest through the underlying managed infrastructure.
Session cookies use HttpOnly, Secure, and SameSite controls where applicable.
Identity + access
How users, admins, API consumers, and protected routes are verified and scoped.
Authentication is handled by Supabase Auth across OAuth, email, and managed session flows.
Authenticated areas are guarded before application content is served.
Admin, platform, customer, and read-only roles are being mapped across product surfaces.
Multi-factor authentication support is planned through Supabase Auth MFA.
Keys + APIs
How Connect and internal platform credentials are issued, stored, and rotated.
API keys map to approved accounts, entitlement tiers, and endpoint permissions.
Raw API keys are shown once at issue time and stored only as hashed values.
Private tokens are kept out of browser bundles and handled through server-side routes.
HMAC-signed delivery is part of the Connect operating roadmap.
Operations
How QSentia tracks incidents, logs, dependencies, pipeline security, and audit readiness.
Security and privacy incidents are triaged against customer, legal, and operating obligations.
Structured access and execution records are available, with downloadable export in progress.
Repository dependency alerts are monitored and reviewed for critical vulnerability impact.
QSentia does not currently hold SOC 2. Target scope is a Type I audit in Q4 2026.
Responsible disclosure
QSentia acknowledges vulnerability reports within 2 business days and prioritizes confirmed issues according to customer and platform risk.
inquiries@qsentia.com