Enterprise Security, Dedicated Single-Tenant Architecture

Your investor data never touches a shared multi-tenant SaaS cloud. Quay is deployed as an isolated, sovereign system dedicated entirely to your organization.

One Dedicated Compose Stack per Customer

Web, worker, Postgres, Redis, MinIO, and SMTP. You (or your operator) run it. TLS and HSTS sit on your reverse proxy, not inside the application container.

Postgres Row-Level Security (RLS)

Tenant tables use FORCE ROW LEVEL SECURITY. The application connects as a non-superuser runtime role. The database migration role is strictly separated.

Staff MFA & Role-Based Access Control

The first user on the staff app becomes Organisation Owner. After that, access is invite-only. Staff sessions require authenticator-app TOTP. There is no public self-service product account on this site.

Strict DPA Gate Before PII Ingestion

Organisation acknowledgement of written DPA terms is cryptographically recorded before investor PII can be uploaded to the document vault.

Comprehensive In-Transit & At-Rest Encryption

TLS in transit. Encrypted storage volumes and object stores at rest, configured to your security specifications. Presigned object URLs expire in minutes. Ask for a vendor due-diligence pack — there is no SOC 2 badge on this page because one has not been claimed.