06Security

SECURITY ISN'T A FEATURE.
IT'S THE FOUNDATION.

QYX20 is built on zero-trust architecture. Every layer — from the network to the application — is independently hardened, continuously monitored, and auditable.

ISO 27001 aligned · SOC 2 Type II in progress

Secure by default

Every module ships with security controls enabled. There is no optional hardening step.

Least privilege

Every service and user receives only the access necessary for their function. Nothing more.

Assume breach

Architecture is designed to contain and detect intrusions, not merely prevent them.

Auditability

Every access and mutation event is logged, timestamped, and cryptographically verifiable.

01Security Architecture

EIGHT LAYERS
OF PROTECTION.

Identity & Authentication

01

Multi-factor authentication, biometric verification, device trust scoring, and session management for every access event. Identity is the first line of defence.

Biometric + MFADevice trust scoringSession lifecycle managementTOTP and hardware key support

Transport Encryption

02

All data in transit is protected by TLS 1.3 with certificate pinning, mutual TLS between internal services, and HSTS enforcement.

TLS 1.3 throughoutCertificate pinningMutual TLS service-to-serviceHSTS enforcement

Data Encryption at Rest

03

Field-level AES-256 encryption at the database layer. Keys managed via HSM with automatic rotation. Sensitive fields are never stored in plaintext.

AES-256 field-level encryptionHSM key managementAutomatic key rotationNo plaintext sensitive storage

Zero-Trust Network

04

No implicit trust between services. Every service-to-service request is authenticated and authorised. Microsegmentation isolates blast radius.

MicrosegmentationmTLS service meshPer-request authorisationLateral movement controls

Compliance & Audit

05

Immutable, tamper-evident audit log for every platform action. Structured export for compliance reporting. GDPR and data residency controls.

Immutable audit trailGDPR data controlsSOC 2 Type II (planned)Structured compliance exports

Threat Detection

06

Real-time anomaly scoring on transaction and access patterns. ML-based fraud signal generation with configurable alert thresholds.

Real-time anomaly scoringML-based fraud signalsVelocity and pattern rulesConfigurable alert routing

Secrets Management

07

All secrets are managed in a centralised vault with ephemeral credential issuance. No long-lived credentials in application code or environment files.

Centralised secrets vaultEphemeral credentialsZero long-lived secretsJust-in-time access

Disaster Recovery

08

Multi-region replication with continuous backups, automated failover testing, and documented recovery procedures.

Multi-region replicationContinuous backupsRTO < 4h / RPO < 1h (target)Automated failover testing

02Trust Model

ZERO TRUST.
ZERO EXCEPTIONS.

No implicit trust is granted to any service, user, or network segment. Every access request is verified, authenticated, and authorised at the point of execution — regardless of origin.

Network

Every service segment is isolated and verified independently.

Identity

Identity assertion required on every request — no session carry-over.

Data access

Field-level permissions enforce least-privilege access to sensitive data.

Secrets

No hardcoded credentials. All secrets issued ephemerally and rotated.

Audit

Every access event is logged to an immutable, append-only audit store.

Found a vulnerability?

We have a responsible disclosure programme. Contact our security team directly and we will respond within 48 hours.

Contact Security Team