SOC 2 Type II Certified

Security at QFS Network

Your portfolio data deserves the same protection as a bank vault. Here’s how we achieve that.

SOC 2 Type II

Our infrastructure and security controls are audited annually by an independent third party against the AICPA SOC 2 Trust Service Criteria.

256-bit encryption

All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Your credentials are hashed with bcrypt — we never store plain-text passwords.

Multi-factor authentication

TOTP-based MFA is available for every account and strongly recommended. We also support hardware security keys via WebAuthn.

Session management

Sessions are cryptographically signed JWTs with short expiry. Changing your password immediately invalidates all other active sessions.

Rate limiting & abuse protection

All authentication and sensitive endpoints are rate-limited per IP and per account. Suspicious activity triggers automated lockout and alerts.

Audit logging

All administrative and sensitive user actions are logged with full context. Logs are immutable and retained for 12 months.

Found a vulnerability?

We take security reports seriously. If you discover a vulnerability, please disclose it responsibly and we’ll work with you to address it quickly.

security@qfsnetwork.com