Developer portal
Security & compliance
Enterprise integrations start with transport security and key hygiene.
Transport
All production API traffic must use HTTPS. Do not send API keys over unencrypted channels.
Key storage
- Store keys in a secrets manager or deployment environment — never in git.
- Rotate keys on a schedule and after personnel changes.
- Browser sandbox keys are public-by-design; use read-only pilot scopes.
RBAC matrix
- viewer — read scans, reports, portfolio, analytics; cannot create schedules or modify remediation.
- operator — default for new keys; scans, schedules, remediation writes, integrations.
- admin — audit log, settings, offboarding, billing portal, partner child tenants.
CAIQ / SIG answer index
- Data classification: customer scan metadata and cryptographic inventory (no PAN).
- Encryption: TLS 1.2+ in transit; Fernet for integration + settings secrets when QTANGL_SECRETS_KEY set.
- Pen test: planned before GA enterprise tier; threat model documented internally.
- Data residency: US default; EU region by enterprise agreement.
- Access control: API keys with roles; SSO documented for dashboard (OIDC).
- Logging: audit log API for tenant admin actions.
- SOC 2: Type I in progress — no certification claim on marketing pages.
Responsible disclosure
Report security issues to charley@qtangl.com. We will acknowledge receipt within two business days during the pilot.
API key rotation
Rotate tenant API keys after personnel changes or suspected exposure. Revoke the old key in admin, issue a new key with the minimum role (viewer for read-only dashboards, operator for scans, admin for billing and audit). Keys are stored as SHA-256 hashes — plaintext is shown once at creation.
Compliance roadmap
SOC 2 readiness and formal data processing agreements are planned for production tenants. Pilot deployments should not process regulated PHI without a signed agreement.
Found an issue? Report documentation feedback