Built for IT and security teams that need asset truth without compromising tenant boundaries or compliance posture.
TLS for agent and API traffic. Production databases and secrets use industry-standard encryption and key management practices.
Multi-tenant RBAC plus Postgres row-level security policies so one customer’s assets, tickets, and agents stay scoped to their tenant.
MFA (TOTP), SSO options (SAML/OIDC), session controls, and least-privilege roles for admins, technicians, and portal users.
Activity trails for sensitive actions, alerting pipelines, and operational logging designed for investigation and compliance evidence.
Run as managed SaaS or self-host with Docker and PostgreSQL on your infrastructure when data residency requires it.
Controls aligned to SOC 2, ISO, and RBI Cyber Security Framework themes (access, logging, change, inventory). External certification and bank-specific RBI assessments require independent auditors — QS Assets is not RBI-certified.
Infrastructure partners that may process customer data for the managed SaaS offering. Self-hosted deployments keep data on your stack. Full register: maintained by NeurQ ops (last public sync 2026-07-21).
For banks, NBFCs, and payment-system operators: product controls map to RBI CSF themes (identity, privileged access, encryption, audit logging, change management, inventory, IR/BCP). This is control design evidence, not RBI certification or approval.
JWT_EXPIRATION=15m)Responsible disclosure: email security@qsasset.com or see security.txt.