QuantProc / Security
Security

Security built in from the first row of the ledger.

Your operations data is the most sensitive thing you'll ever entrust to a vendor. QuantProc treats it that way — with independently audited controls, encryption at every layer, and an immutable record of who touched what.

Trust

Certifications & controls

Independent attestation and the technical controls behind it — so security teams can move from questionnaire to signature faster.

Attestation

SOC 2 Type II

Audited annually by an independent firm against the Security, Availability and Confidentiality trust criteria. The full report is available under NDA.

Certification

ISO 27001

Our information security management system is certified to ISO/IEC 27001, with controls reviewed on a continuous, risk-based cycle.

Privacy

GDPR-ready

A standard Data Processing Agreement, EU data residency options and clear sub-processor disclosure help you meet your own compliance obligations.

Data

Field-level encryption

Sensitive fields are encrypted individually on top of full at-rest encryption, so the most confidential ledger and HR data carries an extra layer of protection.

Identity

SSO / SCIM

SAML and OIDC single sign-on with SCIM provisioning let you manage access from your own identity provider and de-provision instantly on offboarding.

Governance

Immutable audit trail

Every read, change and approval is recorded in a tamper-evident log you can export — giving auditors a complete, trustworthy history of activity.

Infrastructure & hosting

QuantProc runs on hardened cloud infrastructure from a leading provider operating ISO 27001, SOC 2 and PCI-certified data centres. Production environments are logically isolated from development and staging, deployed across multiple availability zones, and protected by network segmentation, managed firewalls and DDoS mitigation. Customer data is never stored on developer workstations.

Encryption

Data is encrypted in transit and at rest by default — there is no opt-out.

  • In transit: all connections use TLS 1.2 or higher, with modern cipher suites and HSTS enforced on every endpoint.
  • At rest: stored data and backups are encrypted with AES-256.
  • Field level: the most sensitive financial and personnel fields receive an additional layer of application-level encryption, with keys managed in a dedicated key-management service and rotated on a regular schedule.

Access control & least privilege

Access to customer data is governed by the principle of least privilege. Internal access is role-based, granted only when required to operate the service, reviewed regularly, and revoked promptly on role change or departure. All staff access requires multi-factor authentication, and privileged actions are logged. On the customer side, granular roles, SSO and SCIM let you enforce your own access policies down to the record.

Monitoring & logging

We continuously monitor our infrastructure and application for anomalous activity. Security events are centralised, retained, and alerted on around the clock. Vulnerability scanning runs continuously, dependencies are tracked for known issues, and independent penetration tests are performed at least annually — a summary of the most recent test is available on request.

Business continuity & disaster recovery

QuantProc is engineered for resilience. Data is backed up automatically with encrypted, geographically separated copies, and recovery procedures are tested regularly against defined recovery-time and recovery-point objectives. Our platform has delivered 99.99% measured uptime, and our status and incident communications keep you informed if anything does go wrong.

Responsible disclosure

We welcome reports from the security research community. If you believe you have found a vulnerability, please email security@quantproc.com with the details. We acknowledge legitimate reports promptly, work with you on remediation, and will not pursue action against good-faith research conducted under our disclosure guidelines.

Sub-processors

We use a limited set of vetted sub-processors for hosting, email and operational tooling. Each is assessed for security and privacy before onboarding and reviewed periodically. A current list of sub-processors, along with our Data Processing Agreement, is available to customers and prospects on request.

Grievance Officer — India (DPDP Act 2023)

In accordance with the Digital Personal Data Protection Act, 2023, QuantProc has designated a Grievance Officer for data principal concerns. Write to privacy@quantproc.com — attn: Suresh Jha, Grievance Officer — and we will respond within 30 days. See our Privacy Policy §14 for full details.

Need our security documentation?

Request our SOC 2 report, pen-test summary and DPA.

Request documents