Navigation
SetupPlatformModules
Pages
DownloadsSecurityPricingDocsBlogContact
Trust Center

Security you can verify

Built for IT and security teams that need asset truth without compromising tenant boundaries or compliance posture.

SOC 2 control mapping in progress
Controls mapped · SOC 2 / ISO path · DPDP Act 2023 · RBI CSF themes
Built for teams that need verifiable tenant isolation and audit evidence.
Badge indicates control design and certification readiness — not a completed SOC 2, ISO, or RBI approval. Regulated banks must complete their own IS assessment; see the RBI control mapping under NDA / docs.

Encryption in transit & at rest

TLS for agent and API traffic. Production databases and secrets use industry-standard encryption and key management practices.

Tenant isolation

Multi-tenant RBAC plus Postgres row-level security policies so one customer’s assets, tickets, and agents stay scoped to their tenant.

Identity & access

MFA (TOTP), SSO options (SAML/OIDC), session controls, and least-privilege roles for admins, technicians, and portal users.

Audit & monitoring

Activity trails for sensitive actions, alerting pipelines, and operational logging designed for investigation and compliance evidence.

Deployment choice

Run as managed SaaS or self-host with Docker and PostgreSQL on your infrastructure when data residency requires it.

Security program readiness

Controls aligned to SOC 2, ISO, and RBI Cyber Security Framework themes (access, logging, change, inventory). External certification and bank-specific RBI assessments require independent auditors — QS Assets is not RBI-certified.

Subprocessors

Infrastructure partners that may process customer data for the managed SaaS offering. Self-hosted deployments keep data on your stack. Full register: maintained by NeurQ ops (last public sync 2026-07-21).

  • Railway (Railway Corp.) — API compute, managed Postgres, Redis. Region: Provider-configured region. Reviewed: 2026-07-21.
  • Vercel (Vercel Inc.) — Web application hosting (Next.js). Region: Provider-configured region. Reviewed: 2026-07-21.
  • Email delivery provider (Per production SMTP/ESP configuration) — Transactional mail (verification, alerts). Region: Per ESP. Reviewed: 2026-07-21.

RBI Cyber Security Framework

For banks, NBFCs, and payment-system operators: product controls map to RBI CSF themes (identity, privileged access, encryption, audit logging, change management, inventory, IR/BCP). This is control design evidence, not RBI certification or approval.

  • Prefer on-prem appliance when residency / segmentation requires it
  • Enforce MFA for privileged users; short-lived sessions (JWT_EXPIRATION=15m)
  • Application passwords: minimum 14 characters with complexity
  • Attach CERT-In empanelled VAPT evidence to change records
Security whitepaperOn-prem setup →Download RBI mapping

Report a vulnerability

Responsible disclosure: email security@qsasset.com or see security.txt.

Platform status →