Loading…
Loading…
Trust & Safety
Last updated: June 2026
Security is foundational to what we do. Our APIs process biometric data on behalf of our customers — that responsibility demands rigorous, layered security controls across our infrastructure, code, and processes.
All data in transit is encrypted with TLS 1.2 or higher. API keys are stored as HMAC-SHA256 hashes — never in plaintext. Backup data is AES-256 encrypted at rest.
Images submitted to production API endpoints may be retained for up to 30 days for operational logging and quality assurance, in isolated, access-controlled storage, then automatically deleted. Demo images are retained for up to 7 days. Processing pipelines run in isolated containers.
Production access is restricted to authorised personnel with MFA enforced. Role-based access control (RBAC) is applied to all internal systems. Access is reviewed quarterly.
All sub-processors are assessed against our security requirements before onboarding. Data processing agreements are in place with all vendors who handle personal data.
Our infrastructure is monitored 24/7 with automated alerting for anomalous API patterns, authentication failures, and infrastructure events. Incidents are triaged within 1 hour by on-call personnel.
We conduct annual penetration tests with independent third-party security firms. Most recent test: Q1 2026. Findings are remediated on a risk-prioritised timeline; critical findings within 72 hours.
Our APIs run on European Union cloud infrastructure. Key controls include:
X-API-Key header. Public demo endpoints are unauthenticated but rate-limited per IP.We apply a data minimisation principle throughout our systems:
We operate a responsible disclosure programme. If you discover a security vulnerability in our Services, please report it to us confidentially. We consider in-scope: quantilence.com, our public API endpoints, and our published mobile or SDK integrations. Out of scope: third-party services, social engineering, and physical security.
Security contact
We acknowledge reports within 24 hours, provide a triage update within 5 business days, and aim to resolve critical findings within 72 hours of confirmation. We will not pursue legal action against researchers who act in good faith, do not access user data beyond what is needed to demonstrate the vulnerability, and follow coordinated disclosure by notifying us before public disclosure.
Our security programme is designed around recognised frameworks and regulations:
For compliance documentation or security questionnaires, email security@quantilence.com.