Trust

Security at TextToQuant.

What we hold, how it is protected, and how to tell us when something is wrong. If anything here is unclear or you need more detail for a review, email security@texttoquant.com.

Reporting a vulnerability

Email security@texttoquant.com. We confirm receipt, keep you updated while we investigate, and credit you when a report leads to a fix, unless you would rather stay anonymous.

Please give us a reasonable window to remediate before disclosing publicly. We will not pursue legal action against good faith research that stays within your own account, avoids degrading the service for others, and does not access, modify or retain data belonging to anyone else.

Machine readable contact details are published at /.well-known/security.txt (RFC 9116).

Authentication and access

Accounts are authenticated through Supabase Auth, with email and password or Google OAuth. Passwords are never stored by TextToQuant.

API keys are issued per account, scoped, and revocable from Account → API keys. AI agents connect over MCP using OAuth 2.1 with dynamic client registration, so a connected agent holds a scoped grant rather than your password, and you can revoke it independently.

Access to production systems is limited to the operators who need it, and administrative surfaces sit behind a separate access layer.

Data in transit and at rest

Every connection is served over TLS. HSTS is enabled site wide with a two year max age and preload, so browsers refuse to fall back to plaintext.

Data at rest lives in managed Postgres with encryption enabled by the provider, and row level security policies scope records to their owning account.

Strategy text, backtest results and account records are retained while your account is active. Account deletion is self serve from Account → Security, and removes your strategies, runs and personal data.

What we store, and what we do not

We store what the product needs: your account, the strategies you write, the runs you execute and their results, and billing records.

We do not hold brokerage credentials, and we never place trades. TextToQuant is a research and simulation tool; it has no connection to any venue where an order could be sent.

Payment card details are handled entirely by the payment provider. Card numbers never reach our servers.

Subprocessors

TextToQuant runs on third party infrastructure. The providers that process data on our behalf are listed in the privacy policy, together with what each one handles.

We review this list when it changes and keep the privacy policy as the single authoritative version rather than maintaining a second copy here that could fall behind it.

Current certification posture

TextToQuant is not currently SOC 2 or ISO 27001 certified. We would rather say that plainly than imply otherwise.

The controls described on this page are in place today. If your procurement process needs a security questionnaire, a DPA, or specific contractual commitments, write to security@texttoquant.com and we will work through it with you.

Availability

Uptime is monitored by an independent third party, and the results are public at status.texttoquant.com, including the incidents, not only the green days.

Long running work continues server side even if a client disconnects, so a dropped connection does not lose a backtest that was already paid for.

© 2026 Text To Quant by Spekule. Not financial advice.