Security & trust

Non-custodial trading security with local keys, crypto and equities alike.

Security by design, not bolted on after. QuantumMind was architected from the trust model outward: your keys stay on your machine, our cloud can only read, and the safety rails, including a full Risk Kernel, are layered, not optional.

Non-custodial

We never hold your funds

No client money ever touches our systems. There's nothing for us to lose, freeze, or misuse.

Local keys

Your key never leaves home

Your trade-only exchange key or local IBKR Gateway connection is stored on your own machine and is never uploaded to us.

Read-only cloud

Our servers can't move money

The cloud shows your dashboard and relays controls you send. It cannot place a trade for you.

The boundary

A hard line your keys and funds never cross.

Everything that can touch your money lives on your computer. Everything on our side is read-only by design.

On your desktop

Everything that matters

  • Your trade-only exchange key or local IBKR Gateway connection: never uploaded
  • The trading engine and nine-agent council, running on your CPU
  • Every order, placed directly from your machine to your own account
  • Full control: pause, adjust the rails, or stop, at any time
On our servers

Read-only by design

  • Your license and which features your plan includes
  • The dashboard view of what your engine is doing
  • Live controls you choose to send back: pause, council, rails
  • No keys. No custody. No ability to move your money.

Principles

Least privilege, all the way down.

Trade-only access

Scoped keys, nothing more

QuantumMind uses exchange keys limited to trading, not withdrawals. Even on your own machine, the engine only has the permission it needs to do its job.

Defense in depth

Rails that don't switch off

The capital floor, daily-loss breaker, regime seatbelt, and the full Risk Kernel beneath them are layered safeguards built into the engine, visible to you, and working whether or not you're watching, on every venue.

Transparent by default

No black box

You can see every agent's vote, every rail, and every order the engine places. Nothing about your account's behavior is hidden from you.

Hardened hosting

Built on enterprise cloud

The read-only dashboard and licensing services run on Microsoft Azure, with the access controls and isolation you'd expect from a security-led build.

Provenance & audit trail

Every decision leaves a permanent, verifiable record.

Trust in a trading engine shouldn't rest on taking our word for it. QuantumMind records what it can prove, not just what it claims.

Decision provenance

Every order, traceable back

Every order QuantumMind places records a hash of the exact market data behind it, which version of the engine was running, the risk configuration in effect, and the resulting exchange order, permanently, alongside the order itself.

Verifiable operating record

Real history, honestly categorized

Runtime, cycles, orders, fills, and risk interventions are tracked and always reported separately for live trading, paper trading, and internal engineering evidence. The three are never blended into one number, so nobody mistakes a test for a track record.

Who built it

Designed by someone who assesses platforms like this for a living.

QuantumMind's trust model isn't marketing language. It reflects a career spent on the security side of high-assurance systems.

  • 20+ years in enterprise cybersecurity
  • CISSP-certified security professional
  • Senior security controls assessor for U.S. government systems
  • Assesses Microsoft Azure platforms at U.S. government assurance levels

Responsible disclosure

Found something? Tell us.

If you believe you've found a security issue in QuantumMind, we want to hear from you. Email us with the details and we'll respond. Please give us a reasonable chance to address it before any public disclosure.

Report a security issue

Private alpha

Control you can verify.

Try it on paper (no exchange account, no keys, nothing at risk) and see the model for yourself.