SECURITY · UPDATED JULY 23, 2026

Security

The visible security posture for this build: holdings only, no trading access, password hashing, signed sessions, and evidence-scoped access controls.

Account and access

Passwords are hashed with PBKDF2-SHA256 before storage. Session tokens are signed and expire.

Private portfolio, watchlist, workspace, and enterprise routes require authentication and scope checks before returning user-owned data.

Financial safety boundary

qyu does not request trading access and cannot move money.

The product should receive holdings and watchlist data only. It should not receive broker passwords, trading PINs, OTPs, API keys with trading permissions, or payment credentials.

Reporting issues

Security reports should include the affected route or screen, steps to reproduce, observed impact, and whether any private data was exposed.

Send security reports to hello@qyu.finance.