Skip to main content

Security

What is in place today, and what is planned.

We keep this page truthful and specific. Below we separate the controls that are already implemented on this website from those that are only planned for future phases.

Implemented on this website today

This is an informational website that does not currently collect personal data, offer accounts, or process any financial transactions. The following controls are already implemented in this codebase:

  • HTTPS enforcement via a Strict-Transport-Security policy.
  • A Content-Security-Policy restricting the origins of scripts, styles, frames and other resources.
  • Hardening headers including X-Content-Type-Options, a referrer policy, a restrictive permissions policy and clickjacking protection.
  • No third-party analytics or marketing trackers are loaded.

Planned for future phases

The following are part of our intended design for when accounts and client functionality are built. They are not yet implemented:

  • Account sign-in with support for Google and, later, passkeys.
  • Application-level two-factor authentication using time-based one-time codes, required before any future financial functionality.
  • Encryption of sensitive data and audit logging of security events.
  • Session management and recovery flows.

We do not claim any security certification, penetration test, specific vendor, or hosting guarantee. Such claims will only appear here once they are true and can be evidenced.

Please note

Descriptions of planned controls are statements of intent, not of completed capability. No system is perfectly secure. If you believe you have found a security issue, please contact us.

Important notice

Quantari is not yet licensed or accepting investors. This website is informational only and is not an offer of, or solicitation for, any financial product, investment service, or investment advice.