QuanFi VMS – Security Overview (Summary)
Effective date: August 21, 2026
Operator: QuanFi LLC
This is a plain-language summary, not a certification or audit report.
Controls (high level)
- HTTPS encryption in transit
- Authentication via managed auth provider (Supabase Auth)
- Authorization with organization membership and roles
- Tenant isolation designed around organization-scoped data and database policies (RLS)
- Private file storage with signed URLs for view/download
- Secrets kept in server environment variables (not in client code)
- Payments handled by Stripe (card data not stored on our servers)
- Access limited for internal staff on a need-to-know basis
Your responsibilities
- Strong passwords and no shared logins
- Correct role assignment
- Lawful vendor data only
- Review AI outputs
- Promptly remove users who leave your company
Incident contact
support@quanfi.app
*QuanFi VMS Security Overview*
Was this page helpful?