An AI-ready financial data gateway inside your perimeter.

QuantJourney Private runs the REST API, Python SDK contract, governed MCP endpoint and connector layer inside your infrastructure. Vendor credentials remain behind the runtime, while agent and application calls keep provider context, request IDs, lineage and audit evidence attached.

Tenancy & Isolation

Every tenant is a hard boundary.

Requests carry a tenant identity end to end. Data, keys, quotas and sessions are scoped to that tenant — there is no shared, ambient access path across customers.

Per-tenant scoping

A tenant identifier is required on governed queries; scopes and roles gate every route, not just the front door.

X-Tenant-Idscopes

Session policy

Per-tenant session limits, idle timeout and absolute lifetime, with admin/user role overrides.

idle timeoutmax sessions

BYOL key mapping

Bring your own vendor licenses: your data-provider keys are stored and used per tenant, never pooled across customers.

BYOLconnectors
Data handling

Your licenses, your data, your keys.

The private product is designed around a simple boundary: customer credentials and provider data stay under customer control.

1. Your provider licenses stay yours.

Credentials are stored per tenant in Vault and used only for requests made by your tenant. They are never pooled, never used to serve another customer, and never used for QuantJourney's own pipelines, datasets or research.

BYOLtenant boundary

2. We don't use your data.

Provider responses fetched with your credentials are returned to you and used for nothing else: not to build QuantJourney datasets, not for other tenants, not for analytics beyond operational metrics, and not to train, fine-tune or evaluate any model.

no poolingno model training

3. Private deployments leave nothing with us.

In a private deployment nothing is stored on QuantJourney infrastructure, and the software makes no outbound connection to QuantJourney other than registry pulls you initiate. What your installation keeps, and for how long, is set by you.

your environmentyour retention

4. Agents get results, not keys.

MCP tools return structured results with provider metadata; raw vendor credentials are never exposed to an agent, a prompt or a client. External AI agents remain governed by your account and that provider's terms.

MCPscoped results
Secrets & Keys

Secrets in Vault. Keys that rotate.

No secrets in code or images. Credentials are issued and read from HashiCorp Vault, and access tokens are short-lived and signed with asymmetric keys.

HashiCorp Vault

Provider credentials, signing keys and service secrets live in Vault with scoped, audited access.

Vaultno hardcoded secrets

RS256 JWT

Access tokens are RS256-signed and short-lived; refresh tokens rotate with reuse (theft) detection.

RS256rotation

API key rotation

Per-tenant API-key rotation policy with warning windows and overdue tracking, surfaced to admins.

key rotationMFA
Governance & Data

Auditable by design.

The platform is built to answer "who accessed what, when, and under which consent" — for your compliance team and ours.

Audit trail

Admin and access events are recorded with actor, action, target, source IP, timestamp and request ID.

audit loglineage

Data retention & DPA

Configurable retention and GDPR-style erasure paths; a Data Processing Agreement is available for institutional customers.

retentionDPA

Consent & suppression

Marketing and communications honor double opt-in, unsubscribe and suppression state centrally.

GDPRopt-in
Resilience

Backed up, replicated, recoverable.

Operational data is backed up and replicated, with recovery paths and monitoring wired into the control plane.

Backups & recovery

Scheduled encrypted backups with recovery tooling and freshness monitoring.

backupsrecovery

Replication

Database replicas for read scale and resilience, monitored for lag and health.

replicamonitoring

Incident response

Alerting, on-call monitoring and an incident process for security and availability events.

alertson-call
Deployment

Hosted or Private Deployment.

Start on QuantJourney Hosted, or license the complete QuantJourney Data Infrastructure runtime for a standard Docker / VM installation inside your environment. Bespoke architecture remains separately scoped.

QuantJourney Hosted

We run and operate the platform; you consume governed routes over REST, SDK and MCP.

fastest start

QuantJourney Private

REST API, Python SDK contract, governed MCP and supported connectors on your standard Docker / VM host. Standard setup is $999 one time; you operate the installation.

$999 / month + $999 setupinside your perimeter

Professional services

Custom Kubernetes, Terraform, IAM, SSO, data-lake integration, bespoke connectors and operating services are quoted separately.

custom scopeSOW
Talk to us

Review the private boundary with us.

Security review depends on network access, credentials and data sensitivity—not contract value. We can walk your team through the architecture, data flow and deployment responsibilities.

QuantJourney API

Share product feedback

✓

Thank you.

Your note is now in the QuantJourney inbox.