SECURITY · UPDATED JULY 23, 2026
Security
The visible security posture for this build: holdings only, no trading access, password hashing, signed sessions, and evidence-scoped access controls.
Account and access
Passwords are hashed with PBKDF2-SHA256 before storage. Session tokens are signed and expire.
Private portfolio, watchlist, workspace, and enterprise routes require authentication and scope checks before returning user-owned data.
Financial safety boundary
qyu does not request trading access and cannot move money.
The product should receive holdings and watchlist data only. It should not receive broker passwords, trading PINs, OTPs, API keys with trading permissions, or payment credentials.
Reporting issues
Security reports should include the affected route or screen, steps to reproduce, observed impact, and whether any private data was exposed.
Send security reports to hello@qyu.finance.