Trust

Quantum AI Security and Compliance Framework

Capital safety and data protection are non-negotiable on the Quantum AI Platform. This page documents the controls in place across encryption, account security, fund segregation, identity verification, compliance, and independent audit.

1. Data Encryption in Transit and at Rest

All traffic between your browser or mobile app and the Quantum AI Platform is encrypted using TLS 1.3 with modern cipher suites. The platform enforces HTTP Strict Transport Security with a one-year max-age and includesSubDomains, which means downgrades to plain HTTP are rejected at the browser level after first contact. Certificate transparency monitoring runs continuously.

User data at rest — including personal information, KYC artifacts, and historical trade records — is stored in encrypted database volumes with envelope encryption keys held in a managed key service. Encryption keys rotate quarterly; access to decryption is restricted to specific service identities and is logged in an immutable audit trail.

Backup snapshots are stored in geographically separated regions and are themselves encrypted with rotated keys. Backup retention is bounded by data minimization policy: records older than the regulatory retention window are deleted automatically.

2. Account-Level Security Controls

Every user account requires two-factor authentication. Time-based one-time passwords (TOTP) through authenticator apps are the default; SMS-based OTP is supported as a fallback but discouraged due to the well-documented weaknesses of SMS as a second factor. Pro tier users may enable WebAuthn hardware keys for phishing-resistant authentication.

Sensitive operations — withdrawal initiation, risk-profile changes outside your configured envelope, banking detail updates — require a fresh second-factor confirmation regardless of session age. Session tokens expire after a configurable idle window and are rotated on every privilege change.

Login activity is logged with IP, geolocation hint, and device fingerprint. Users receive an email notification for every new device login. Suspicious patterns trigger a soft lock that requires identity reverification before the account can resume normal operations.

3. Segregation of Client Funds

Quantum AI Platform does not custody user funds directly. Trading capital is held in segregated client accounts at partner brokers, separated from the platform's own operating funds. This separation is enforced at the broker level and is reflected in account-opening contracts that users sign as part of onboarding.

The segregation principle means that in any scenario where the platform itself encountered operational difficulty, user capital would remain accessible directly through the partner broker. The platform provides analysis and execution; the broker provides custody. Each role is independent of the other.

Withdrawal flows return funds to the original source. Funds deposited via UPI return via UPI; funds wired internationally are returned via wire. This path consistency is a deliberate anti-fraud control and is enforced by both platform-side checks and broker-side compliance.

4. KYC and Identity Verification

KYC verification is mandatory for every account. The process requests PAN, address documentation, and a live selfie capture matched against the submitted identity document. Verification is performed in cooperation with regulated KYC providers; the platform itself does not store raw biometric artifacts longer than the verification window.

KYC submissions are typically processed within the same business day. Higher-risk profiles — sanctioned jurisdictions, PEP status, anomalous documentation — receive enhanced due diligence and may take longer. The platform's AML policy is aligned with FATF recommendations and is reviewed annually.

Once verified, users are not asked to repeat KYC for routine activity. However, periodic re-verification may be requested for stale documents or for material profile changes. All re-verification flows respect the original data minimization principle: only what is necessary is requested, and supporting documents are not retained beyond what is required.

5. Compliance Standards and Alignment

Quantum AI Platform is a technology provider, not a SEBI-registered investment advisor. The platform does not solicit deposits as an investment scheme and does not promise specific returns. All references to historical performance on the website are clearly identified as simulated or historical, with the standard performance disclaimer attached.

Data handling practices are aligned with the EU General Data Protection Regulation and the principles of the Digital Personal Data Protection Act 2023 in India. Users have the right to access, correct, export, and delete their personal data. Requests are handled within thirty days of receipt.

The platform's security architecture is designed against ISO 27001 controls. Formal certification is in progress; the controls themselves are operational and tested. Internal audit results are summarized in the platform's annual transparency report, published on this page each January.

6. Independent Audits and Vulnerability Disclosure

Quantum AI engages independent security firms to perform external penetration testing twice a year. Audit reports are reviewed by the platform's security engineering team and remediated findings are tracked through a public summary on the transparency report.

A responsible disclosure program is open to external security researchers. Eligible reports of confirmed vulnerabilities are eligible for a recognition bounty, with severity-graded payouts. The disclosure email is security@quantum-ai.com.in and the platform's PGP key is available on request through the same channel.

Internal monitoring covers anomaly detection on authentication, withdrawal patterns, and inter-service traffic. Alerts are routed to a 24×7 security operations rotation. The platform commits to user notification within 72 hours for any confirmed incident that materially affects account security.

Questions about security?

Write to security@quantum-ai.com.in or, for general support, support@quantum-ai.com.in.

Open Your Quantum AI Account →

Risk Disclosure. Trading involves substantial risk of loss and is not suitable for every investor. AI-assisted automated trading does not eliminate market risk; it manages it within configured parameters.

Regulatory Note. Quantum AI is a technology platform and is not a SEBI-registered investment advisor. We do not provide personalized investment advice. Users should consult a qualified financial advisor and review tax implications with a chartered accountant.

Performance Disclaimer. Past performance is not indicative of future results. Returns referenced on this website are simulated or historical and do not guarantee specific outcomes for any individual user.