Security

Financial data protected by layered, tenant-aware controls.

FinQ Pulse applies layered controls across data, identity, access and approval workflows: encryption, MFA, role-based access, organizational isolation and detailed audit logging.

AWS Frankfurt region Tenant isolated MFA protected
Application data location

Application data hosted in AWS Frankfurt.

FinQ Technologies and Consulting is registered in the Republic of Armenia. FinQ Pulse application data is hosted in AWS eu-central-1, Frankfurt, Germany; the hosting location does not represent the company’s place of registration.

AWS REGIONeu-central-1Frankfurt, DE
01 · ENCRYPTION AT REST

Layered protection for stored data.

Platform data is protected by infrastructure encryption, while sensitive analytical values receive additional protection before they are written to the database.

  • Encryption for database and object storage
  • Additional encryption for sensitive analytical data
  • Protection for multi-factor authentication secrets
  • Integrity controls for uploads and generated reports
02 · ENCRYPTION IN TRANSIT

Encrypted connections for external and internal traffic.

User access to the platform is protected by HTTPS, and connections between key services and the database require encrypted transport.

  • HTTPS for user access
  • Encrypted connections between platform services
  • Secure controls for user sessions
  • Encrypted database connections
03 · IDENTITY AND ACCESS

Multi-factor authentication and role-based access control.

MFA is required for privileged roles and can be applied to all users according to organizational policy. Access to actions and data is restricted by assigned roles.

  • Defined roles for analysis, review, leadership, administration and audit
  • Controlled user-session lifetime
  • Login rate limits and account-lockout controls
  • Protection for user sessions and requests
04 · TENANT ISOLATION

One organization cannot access another organization’s data.

Isolation is applied across multiple platform layers: organizational context follows requests, the database independently restricts data access, and object storage separates organizational data.

  • Independent access restrictions at the database layer
  • Safe behavior when organizational context is absent
  • Segregated object storage by organization
05 · AUDITABILITY

Traceable history for operations, approvals and calculations.

The audit log records material actions and security events with organizational, user, resource and time context. Sensitive values in the audit record are redacted.

  • Scenario creation, updates and workflow transitions
  • Authentication and MFA events
  • Workflow comment and state history
  • Calculation provenance and result-integrity references
Defense in depth

Controls remain effective even when one layer is bypassed.

Role-based access does not stand alone. Data policies independently constrain access, sensitive analytical information receives additional encryption, and report generation remains gated by workflow state.

01IdentityMFA · protected sessions
02PlatformRole-based access · request protection
03DataEncryption · isolation · integrity controls
04InfrastructureFrankfurt · encrypted transport

Security diligence

The controls described here reflect the current FinQ Pulse platform and infrastructure implementation. They do not imply a certification or independent audit that has not yet been completed. Detailed technical review materials can be shared during a qualified pilot discussion.

Start a security review