Security
Last updated: 24 August 2026
This page describes security controls evidenced in the current Quantara implementation and the boundaries users must understand before processing project information.
Security is a shared responsibility. Quantara does not claim certification, guaranteed availability, absolute security or guaranteed output accuracy.
Authentication and sessions
Passwords are hashed with bcrypt before storage. Protected areas use first-party database sessions and HttpOnly cookies that are Secure in production and SameSite=Lax.
Session tokens are stored as hashes and expire after 30 days. Email verification and account status checks form part of protected access.
Company and project separation
Authenticated API paths use current user and company identifiers and apply company or project authorization checks before protected records are returned or changed.
Roles and entitlements restrict supported actions. Customers must still manage their own users, permissions and internal approval processes.
Files and generated documents
Production project files and generated documents are designed to use private object storage rather than public local-disk storage. Customer-specific hosting or regional requirements must be agreed before sensitive project data is uploaded.
Supported project-file deletion removes the database record and stored bytes. Generated-document deletion removes its record and attempts object deletion. Project deletion archives the project rather than erasing every related record.
Integrations and voice workflows
OAuth credentials are encrypted with AES-256-GCM before their ciphertext is stored in PostgreSQL and are cleared on disconnect. Google Drive uses read-only authorization for user-selected supported file imports.
When configured, voice audio may be sent to OpenAI for transcription and a transcript may be interpreted into a proposal. A user must review and confirm before governed BOQ data changes.
Payment boundaries
Configured recurring checkout sends necessary company and price references to Stripe. Quantara stores provider identifiers and subscription state but does not store card numbers in its own schema.
Audit records and incident reports
Implemented workflows record relevant timestamps, actors and state transitions for supported operations. This does not establish continuous external monitoring or a public real-time status service.
Report suspected account compromise, unauthorized access or a security issue through the verified contact channel. Do not include credentials or confidential project files in the first report.
Confirmed limitations
- No ISO, SOC, PCI or other security certification is claimed on this page.
- No static 'all systems nominal' statement is used without a real public health mechanism.
- Security controls do not replace professional review of extraction, quantities, rates or documents.
- Live hosting, database, storage, email and processing regions must be confirmed by the owner before contractual publication.
Customer-specific contracting details, service regions, transfer safeguards, retention requirements and commercial terms are confirmed in the applicable order form, quotation or written agreement before a paid enterprise commitment.
Contact and privacy requests
Use the verified channels below for privacy rights, security reports, legal questions and support. Do not send passwords, authentication tokens or confidential project documents by email or WhatsApp.
- Email: solution@vistabylara.com
- Telephone: +971 50 799 4292
- WhatsApp: +971 50 799 4292