Trust Center
Security architecture
How Qtangl processes scan data, protects credentials, and signs reports.
Data flow
API requests authenticate with tenant API keys (hashed at rest). Scan jobs queue in Redis; workers execute discovery, persist bundles in Postgres per tenant, and run post-complete diff/alert/webhook pipelines.
Encryption
TLS in transit for all public endpoints. Integration secrets (Jira tokens) encrypt at rest when QTANGL_SECRETS_KEY is configured. Webhooks support optional HMAC signing.
Report integrity
Reports include content hashes and signatures (ML-DSA-65 or Ed25519). Verify at /verify.
Vulnerability disclosure
Report security issues responsibly to charley@qtangl.com (subject [SECURITY]) or see our disclosure policy. Include reproduction steps, impact assessment, and your preferred contact method. We aim to acknowledge reports within 2 business days.
Canonical policy: /.well-known/security.txt
Penetration testing
Independent penetration testing is scoped in our internal pen-test scope document. Executive summary available under NDA on document request. Last pen test: not yet executed — scheduled before first regulated pilot.
Security overview
Download the security overview for architecture, encryption, sub-processors, and honest SOC 2 status.
Acknowledgments
We maintain this page as the acknowledgments destination referenced in our security.txt file. Security researchers who report valid vulnerabilities in scope will be listed here with permission after remediation.
No public acknowledgments yet — we are early in our disclosure program. Thank you to everyone who reports issues responsibly.
- Contact
- charley@qtangl.com
- Policy
- Disclosure policy
- Expires
- 2027-06-01