LEGAL / SECURITY
Security
Last updated: [Last updated]
Template — review with qualified legal counsel before launch. Bracketed fields must be completed, and the content adapted to your entity and jurisdiction.
Security is foundational to Quantume. This page summarises the practices we apply to protect the platform and the data it processes, and explains how to report a vulnerability responsibly. It describes the design intent of the Quantume platform; specific contractual commitments to a bank are set out in that bank's agreement.
1. Our approach
We take a defence-in-depth approach: layered controls across infrastructure, application, data and operations, so that no single failure compromises security. Security is built into how we design, build and run the platform rather than added afterwards.
2. Encryption
We are designed to encrypt data in transit using current TLS standards, and to encrypt sensitive data at rest. Cryptographic keys are managed through dedicated key-management practices with restricted access.
3. Access control and tenant isolation
Access to systems and data follows least-privilege and role-based access principles, with authentication and authorisation enforced at every entry point. The platform is multi-tenant by design, with strict isolation so that one bank's data is never accessible to another.
4. Auditability
The platform is designed to record an immutable, tamper-evident audit trail of state changes, supporting investigation, accountability and regulatory examination.
5. Secure software development
We follow a secure software development lifecycle that includes code review, automated testing, dependency and vulnerability scanning, and change-management controls before changes reach production.
6. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please email [email protected] with enough detail to reproduce the issue. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and avoid accessing or modifying data that is not yours.
We will not pursue or support legal action against researchers who act in good faith, follow this policy, and avoid privacy violations, service disruption or data destruction. We aim to acknowledge reports promptly and keep you informed as we work toward a fix.
7. Scope
This policy covers the Quantume platform and this website. Testing must be non-destructive: no denial-of-service, no social engineering of staff, and no automated scanning that degrades service. Do not access, alter or exfiltrate data belonging to others.
8. Certifications and roadmap
Quantume is designed to support recognised security and banking standards, and we are working toward formal certifications and independent assessments as the platform matures. We describe these as goals on our roadmap and do not claim certifications we have not yet achieved. Current certification status can be confirmed on request.
9. Contact
For security matters, contact [email protected]. For privacy matters, see our Privacy Policy.