Your data, protected
QuantRidge is built with security as a first principle — not an afterthought. From encryption to compliance, every layer is designed to meet the demands of institutional finance.
Defense in depth
Multiple overlapping layers of security — because no single control is enough.
Enterprise Encryption
Strong encryption in transit (TLS). At-rest protection is provided by our managed hosting and database providers according to their security programs.
Access Control
Role-based access control with fine-grained permissions, multi-factor authentication, and session review and revocation. Firms needing SSO or a specific identity provider should ask us what is available on their plan before subscribing.
Audit Trails
Timestamped audit logging of account and administrative actions, retained per our published schedule. Business workspaces get a firm-wide audit trail; ask us for the current scope if you have a specific compliance requirement.
Vulnerability Management
Secure development practices, dependency and vulnerability monitoring, and a published route for good-faith security research. We have not yet completed a third-party penetration test; when we do, we will say so here and share the summary with business customers under NDA rather than imply one exists.
Incident Response
A documented incident response plan with a 24-hour internal response target for critical issues, and the contractual 72-hour breach notification in our DPA. Security events are classified, contained, and resolved with full post-mortems.
Data Privacy
Your data is yours. We never sell it, never train models on it, and provide export and deletion tooling. GDPR and CCPA data subject rights supported.
Privacy & legal alignment
We publish clear policies and support data-subject requests. Third-party subprocessors may hold their own certifications; QuantRidge does not represent that the application itself is SOC 2 certified unless separately disclosed.
Privacy Policy · California notice · DPA · Subprocessors
Vendor management
Every third party that touches customer data is named on our subprocessors page with its purpose, the categories of data it receives, and where it processes them. Each is bound by written terms no less protective than our own commitments, and we publish a new subprocessor at least 30 days before it begins processing so customers can object.
Breach notification
If a breach affects your personal data, we notify affected business customers without undue delay and within 72 hours of becoming aware, with what we know at the time and follow-up as the investigation proceeds. That commitment is contractual, not aspirational — it is clause 6 of our DPA.
What we do not claim
QuantRidge does not currently hold its own SOC 2 Type II or ISO 27001 certification, and we will not imply otherwise by pointing at our providers' badges. Our infrastructure providers maintain their own certifications; those attest to their controls, not ours. We are not a bank, custodian, or broker-dealer, and customer assets are never held by us — they stay at your own institution, and our connections are read-only. If we obtain an independent audit we will publish the report reference here and date it. Until then, the measures described on this page are our own representations, and we will answer a security questionnaire in writing for any customer who asks.
Found a vulnerability?
We take security reports seriously. If you discover a potential vulnerability in the QuantRidge platform, please disclose it responsibly — we'll acknowledge your report within 24 hours.
We do not pursue legal action against good-faith security researchers.
Report a Vulnerabilitysupport@quantridge.net · Encrypted email available on request