QSentia Platform

Quantitative products, agents, platforms, and Connect APIs are open for approved institutional partners.

Explore solutions

Trust center

Governance and security for institutional AI decisions.

QSentia connects model intelligence to capital only through guarded access, human review, evidence records, and operational controls.

Trust posture

Evidence first. Authority only after controls.

TLS

Encrypted traffic

RLS

Supabase data controls

Hashed

API key storage

Q4 2026

SOC 2 Type I target

QSentia does not currently claim SOC 2 or ISO certification. Current controls are self-assessed while third-party validation is prepared.

Institutional guardrails

Trust is built into the decision architecture.

The trust model is intentionally practical: protect access, preserve evidence, separate review from authority, and make control status visible instead of implied.

Human approval

Capital authority remains gated by review, entitlement, and approval state.

Decision evidence

Signals, portfolio context, risk decisions, approvals, and outcomes stay attached to the record.

Secure access

Authentication, server-side credentials, scoped keys, and route controls keep private workflows protected.

Control status

Clear status, no overclaiming.

Implemented controls, active work, and planned validation are separated so institutional partners can review the platform honestly.

ImplementedIn progressPlanned

Transport + storage

Encryption controls

How QSentia protects sessions, browser traffic, and persisted production data.

TLS 1.2 / 1.3 in transit

All client traffic is encrypted over HTTPS, with no plain HTTP application fallback.

Implemented

AES-256 encryption at rest

Production Supabase data is encrypted at rest through the underlying managed infrastructure.

Implemented

Secure cookie flags

Session cookies use HttpOnly, Secure, and SameSite controls where applicable.

Implemented

Identity + access

Authentication and permissions

How users, admins, API consumers, and protected routes are verified and scoped.

Supabase Auth

Authentication is handled by Supabase Auth across OAuth, email, and managed session flows.

Implemented

Protected route middleware

Authenticated areas are guarded before application content is served.

Implemented

Role-based access control

Admin, platform, customer, and read-only roles are being mapped across product surfaces.

In progress

MFA / 2FA

Multi-factor authentication support is planned through Supabase Auth MFA.

Planned

Keys + APIs

API key lifecycle

How Connect and internal platform credentials are issued, stored, and rotated.

Scoped key issuance

API keys map to approved accounts, entitlement tiers, and endpoint permissions.

Implemented

Hashed key storage

Raw API keys are shown once at issue time and stored only as hashed values.

Implemented

Server-side token handling

Private tokens are kept out of browser bundles and handled through server-side routes.

Implemented

Webhook signing

HMAC-signed delivery is part of the Connect operating roadmap.

Planned

Operations

Governance and monitoring

How QSentia tracks incidents, logs, dependencies, pipeline security, and audit readiness.

Incident response process

Security and privacy incidents are triaged against customer, legal, and operating obligations.

In progress

Audit log exports

Structured access and execution records are available, with downloadable export in progress.

In progress

Dependency vulnerability scanning

Repository dependency alerts are monitored and reviewed for critical vulnerability impact.

Implemented

SOC 2 Type I audit

QSentia does not currently hold SOC 2. Target scope is a Type I audit in Q4 2026.

Planned

Responsible disclosure

Report security concerns before public disclosure.

QSentia acknowledges vulnerability reports within 2 business days and prioritizes confirmed issues according to customer and platform risk.

inquiries@qsentia.com