Security
Handling records that people are accountable for.
Title records contain non-public personal information. Investment data is commercially sensitive. Both carry obligations that outlast any single transaction, so security is designed into how our platforms work rather than added around them.
How we think about it
Your data is yours
Clients own their records, their plants and their research. We don't aggregate client data across accounts, we don't resell it, and we don't train models on it.
Isolation by default
Each client's environment is separated from every other. There is no shared pool of client data and no path by which one client's records become visible to another.
Nothing commits unreviewed
Automated extraction and analysis produce candidates; a person approves before anything is written to a production system. This is a data quality control and a security control at once — it means no automated process can silently alter a client's records.
Everything leaves a trail
Source file, extraction history, reviewer, approval, export. Lineage is a property of how the systems are built, not a report generated afterwards.
How data is protected
In transit
All connections are encrypted using current TLS standards. Administrative access to systems handling client data is over authenticated, encrypted channels only.
At rest
Client data is encrypted at rest. Credentials used by our services are protected using operating-system-level encryption and are never stored in source code or configuration held in version control.
Access
Role-based access control governs who can see and do what. Access to production systems is limited to personnel who need it for a defined purpose. Access to production systems and data operations are logged.
Separation of duties
Development, review and production deployment are separate functions carried out by different people. No single individual moves a change from authorship to production unreviewed.
How we build
Code review
All changes are reviewed by another developer before they are merged. Version control retains a full history of what changed, when and why.
Dependency review
Dependencies are reviewed for known vulnerabilities as part of our release process.
Change control and recovery
Changes to production go through a defined build and deployment process rather than direct edits to running systems, with the ability to roll back a release. Automated backups are taken at defined points, including at each major phase boundary during county plant construction, so a build can be restored to a known-good state.
Regulatory context
GLBA
Title agents and settlement service providers handle non-public personal information and are subject to the Gramm-Leach-Bliley Act's safeguards requirements. Our platforms are designed to support clients meeting those obligations — isolation, access control, encryption, and an auditable record of who did what.
CCPA
We support clients in responding to consumer requests regarding personal information held in systems we provide.
Data processing terms
Where we process personal data on a client's behalf, that processing is governed by the agreement between us, including data processing terms setting out purpose, scope and obligations.
What we are not
Quantius is a software and data services company. We are not a title agent, not an underwriter, and not a registered investment adviser, broker-dealer or other regulated financial services provider.
Certification status
Quantius does not currently hold SOC 2 or ISO 27001 certification. We would rather say that plainly than imply otherwise.
The controls described above are in place and in use. Formal certification is a matter of independent audit, and we will say so here when it has been completed rather than before.
Reporting a security issue
If you believe you've found a security vulnerability in any Quantius system, email email us with enough detail to reproduce it. We'll acknowledge your report and keep you informed while we investigate.
Please don't publicly disclose an issue before we've had a reasonable opportunity to address it.
Questions about security
If you're evaluating Quantius and need detail beyond this page — for a vendor review, a security questionnaire, or your own due diligence — get in touch and we'll work through it with you.