sessions
HTTP-only cookies
// legal
Quanta keeps public security statements tied to controls that are already present in the product.
Password authentication stores bcrypt hashes. Production sessions use HTTP-only, Secure, SameSite=Lax cookies.
Personal, Tax, Trader, and Admin access are tiered. Protected workspaces and server routes enforce tier checks.
Plaid handles bank credential collection. Quanta receives the tokens and account data needed to sync supported accounts.
Security questions, suspected vulnerabilities, and diligence requests can be sent to the security inbox for review.