Skip to main content

Security

Last updated: 24 August 2026

This page describes security controls evidenced in the current Quantara implementation and the boundaries users must understand before processing project information.

Security is a shared responsibility. Quantara does not claim certification, guaranteed availability, absolute security or guaranteed output accuracy.

Authentication and sessions

Passwords are hashed with bcrypt before storage. Protected areas use first-party database sessions and HttpOnly cookies that are Secure in production and SameSite=Lax.

Session tokens are stored as hashes and expire after 30 days. Email verification and account status checks form part of protected access.

Company and project separation

Authenticated API paths use current user and company identifiers and apply company or project authorization checks before protected records are returned or changed.

Roles and entitlements restrict supported actions. Customers must still manage their own users, permissions and internal approval processes.

Files and generated documents

Production project files and generated documents are designed to use private object storage rather than public local-disk storage. Customer-specific hosting or regional requirements must be agreed before sensitive project data is uploaded.

Supported project-file deletion removes the database record and stored bytes. Generated-document deletion removes its record and attempts object deletion. Project deletion archives the project rather than erasing every related record.

Integrations and voice workflows

OAuth credentials are encrypted with AES-256-GCM before their ciphertext is stored in PostgreSQL and are cleared on disconnect. Google Drive uses read-only authorization for user-selected supported file imports.

When configured, voice audio may be sent to OpenAI for transcription and a transcript may be interpreted into a proposal. A user must review and confirm before governed BOQ data changes.

Payment boundaries

Configured recurring checkout sends necessary company and price references to Stripe. Quantara stores provider identifiers and subscription state but does not store card numbers in its own schema.

Audit records and incident reports

Implemented workflows record relevant timestamps, actors and state transitions for supported operations. This does not establish continuous external monitoring or a public real-time status service.

Report suspected account compromise, unauthorized access or a security issue through the verified contact channel. Do not include credentials or confidential project files in the first report.

Confirmed limitations

  • No ISO, SOC, PCI or other security certification is claimed on this page.
  • No static 'all systems nominal' statement is used without a real public health mechanism.
  • Security controls do not replace professional review of extraction, quantities, rates or documents.
  • Live hosting, database, storage, email and processing regions must be confirmed by the owner before contractual publication.

Customer-specific contracting details, service regions, transfer safeguards, retention requirements and commercial terms are confirmed in the applicable order form, quotation or written agreement before a paid enterprise commitment.

Contact and privacy requests

Use the verified channels below for privacy rights, security reports, legal questions and support. Do not send passwords, authentication tokens or confidential project documents by email or WhatsApp.

Is Quantara right for your team?

Our automated sales advisor helps you choose your next step. OpenAI may process your message. Please leave out confidential information. Privacy

Quantara Security and Account Access