Security and control

Boundaries before automation.

Tenant and entity isolation

Customer organisations and connected entities must have separate authorisation, records, roles, memory, documents and audit histories. Portfolio reporting does not remove source-ledger boundaries.

Controlled financial actions

Material actions require a preview, validation, duplicate prevention and an applicable approval. Tax, payment, payroll, filing, destructive and legally significant actions require human confirmation every time.

Credentials and data

QConnect uses separate infrastructure and credentials from QFetch. Sensitive credentials are stored as platform secrets rather than in source code. Stored sensitive data must be encrypted and governed by access and retention controls.

Reporting concerns

Security reports should be sent to support@getqconnect.com. Do not include passwords, tokens, bank details or live customer financial records in an initial report.

This page describes the intended production controls. QConnect remains in sandbox development and will undergo testing before live release.