Skip to content

Trust Center

Security architecture

How Qtangl processes scan data, protects credentials, and signs reports.

Data flow

API requests authenticate with tenant API keys (hashed at rest). Scan jobs queue in Redis; workers execute discovery, persist bundles in Postgres per tenant, and run post-complete diff/alert/webhook pipelines.

Qtangl data flow diagram

Encryption

TLS in transit for all public endpoints. Integration secrets (Jira tokens) encrypt at rest when QTANGL_SECRETS_KEY is configured. Webhooks support optional HMAC signing.

Report integrity

Reports include content hashes and signatures (ML-DSA-65 or Ed25519). Verify at /verify.

Vulnerability disclosure

Report security issues responsibly to charley@qtangl.com (subject [SECURITY]) or see our disclosure policy. Include reproduction steps, impact assessment, and your preferred contact method. We aim to acknowledge reports within 2 business days.

Canonical policy: /.well-known/security.txt

Penetration testing

Independent penetration testing is scoped in our internal pen-test scope document. Executive summary available under NDA on document request. Last pen test: not yet executed — scheduled before first regulated pilot.

Security overview

Download the security overview for architecture, encryption, sub-processors, and honest SOC 2 status.

Acknowledgments

We maintain this page as the acknowledgments destination referenced in our security.txt file. Security researchers who report valid vulnerabilities in scope will be listed here with permission after remediation.

No public acknowledgments yet — we are early in our disclosure program. Thank you to everyone who reports issues responsibly.

Contact
charley@qtangl.com
Expires
2027-06-01

← Trust Center