Skip to content

Developer portal

Security & compliance

Enterprise integrations start with transport security and key hygiene.

Transport

All production API traffic must use HTTPS. Do not send API keys over unencrypted channels.

Key storage

  • Store keys in a secrets manager or deployment environment — never in git.
  • Rotate keys on a schedule and after personnel changes.
  • Browser sandbox keys are public-by-design; use read-only pilot scopes.

RBAC matrix

  • viewer — read scans, reports, portfolio, analytics; cannot create schedules or modify remediation.
  • operator — default for new keys; scans, schedules, remediation writes, integrations.
  • admin — audit log, settings, offboarding, billing portal, partner child tenants.

CAIQ / SIG answer index

  • Data classification: customer scan metadata and cryptographic inventory (no PAN).
  • Encryption: TLS 1.2+ in transit; Fernet for integration + settings secrets when QTANGL_SECRETS_KEY set.
  • Pen test: planned before GA enterprise tier; threat model documented internally.
  • Data residency: US default; EU region by enterprise agreement.
  • Access control: API keys with roles; SSO documented for dashboard (OIDC).
  • Logging: audit log API for tenant admin actions.
  • SOC 2: Type I in progress — no certification claim on marketing pages.

Responsible disclosure

Report security issues to charley@qtangl.com. We will acknowledge receipt within two business days during the pilot.

API key rotation

Rotate tenant API keys after personnel changes or suspected exposure. Revoke the old key in admin, issue a new key with the minimum role (viewer for read-only dashboards, operator for scans, admin for billing and audit). Keys are stored as SHA-256 hashes — plaintext is shown once at creation.

Compliance roadmap

SOC 2 readiness and formal data processing agreements are planned for production tenants. Pilot deployments should not process regulated PHI without a signed agreement.