06Security
SECURITY ISN'T A FEATURE.
IT'S THE FOUNDATION.
QYX20 is built on zero-trust architecture. Every layer — from the network to the application — is independently hardened, continuously monitored, and auditable.
Secure by default
Every module ships with security controls enabled. There is no optional hardening step.
Least privilege
Every service and user receives only the access necessary for their function. Nothing more.
Assume breach
Architecture is designed to contain and detect intrusions, not merely prevent them.
Auditability
Every access and mutation event is logged, timestamped, and cryptographically verifiable.
01Security Architecture
EIGHT LAYERS
OF PROTECTION.
Identity & Authentication
01Multi-factor authentication, biometric verification, device trust scoring, and session management for every access event. Identity is the first line of defence.
Transport Encryption
02All data in transit is protected by TLS 1.3 with certificate pinning, mutual TLS between internal services, and HSTS enforcement.
Data Encryption at Rest
03Field-level AES-256 encryption at the database layer. Keys managed via HSM with automatic rotation. Sensitive fields are never stored in plaintext.
Zero-Trust Network
04No implicit trust between services. Every service-to-service request is authenticated and authorised. Microsegmentation isolates blast radius.
Compliance & Audit
05Immutable, tamper-evident audit log for every platform action. Structured export for compliance reporting. GDPR and data residency controls.
Threat Detection
06Real-time anomaly scoring on transaction and access patterns. ML-based fraud signal generation with configurable alert thresholds.
Secrets Management
07All secrets are managed in a centralised vault with ephemeral credential issuance. No long-lived credentials in application code or environment files.
Disaster Recovery
08Multi-region replication with continuous backups, automated failover testing, and documented recovery procedures.
02Trust Model
ZERO TRUST.
ZERO EXCEPTIONS.
No implicit trust is granted to any service, user, or network segment. Every access request is verified, authenticated, and authorised at the point of execution — regardless of origin.
Network
Every service segment is isolated and verified independently.
Identity
Identity assertion required on every request — no session carry-over.
Data access
Field-level permissions enforce least-privilege access to sensitive data.
Secrets
No hardcoded credentials. All secrets issued ephemerally and rotated.
Audit
Every access event is logged to an immutable, append-only audit store.
Found a vulnerability?
We have a responsible disclosure programme. Contact our security team directly and we will respond within 48 hours.