Per-tenant scoping
A tenant identifier is required on governed queries; scopes and roles gate every route, not just the front door.
QuantJourney Private runs the REST API, Python SDK contract, governed MCP endpoint and connector layer inside your infrastructure. Vendor credentials remain behind the runtime, while agent and application calls keep provider context, request IDs, lineage and audit evidence attached.
Requests carry a tenant identity end to end. Data, keys, quotas and sessions are scoped to that tenant — there is no shared, ambient access path across customers.
A tenant identifier is required on governed queries; scopes and roles gate every route, not just the front door.
Per-tenant session limits, idle timeout and absolute lifetime, with admin/user role overrides.
Bring your own vendor licenses: your data-provider keys are stored and used per tenant, never pooled across customers.
The private product is designed around a simple boundary: customer credentials and provider data stay under customer control.
Credentials are stored per tenant in Vault and used only for requests made by your tenant. They are never pooled, never used to serve another customer, and never used for QuantJourney's own pipelines, datasets or research.
Provider responses fetched with your credentials are returned to you and used for nothing else: not to build QuantJourney datasets, not for other tenants, not for analytics beyond operational metrics, and not to train, fine-tune or evaluate any model.
In a private deployment nothing is stored on QuantJourney infrastructure, and the software makes no outbound connection to QuantJourney other than registry pulls you initiate. What your installation keeps, and for how long, is set by you.
MCP tools return structured results with provider metadata; raw vendor credentials are never exposed to an agent, a prompt or a client. External AI agents remain governed by your account and that provider's terms.
No secrets in code or images. Credentials are issued and read from HashiCorp Vault, and access tokens are short-lived and signed with asymmetric keys.
Provider credentials, signing keys and service secrets live in Vault with scoped, audited access.
Access tokens are RS256-signed and short-lived; refresh tokens rotate with reuse (theft) detection.
Per-tenant API-key rotation policy with warning windows and overdue tracking, surfaced to admins.
The platform is built to answer "who accessed what, when, and under which consent" — for your compliance team and ours.
Admin and access events are recorded with actor, action, target, source IP, timestamp and request ID.
Configurable retention and GDPR-style erasure paths; a Data Processing Agreement is available for institutional customers.
Marketing and communications honor double opt-in, unsubscribe and suppression state centrally.
Operational data is backed up and replicated, with recovery paths and monitoring wired into the control plane.
Scheduled encrypted backups with recovery tooling and freshness monitoring.
Database replicas for read scale and resilience, monitored for lag and health.
Alerting, on-call monitoring and an incident process for security and availability events.
Start on QuantJourney Hosted, or license the complete QuantJourney Data Infrastructure runtime for a standard Docker / VM installation inside your environment. Bespoke architecture remains separately scoped.
We run and operate the platform; you consume governed routes over REST, SDK and MCP.
REST API, Python SDK contract, governed MCP and supported connectors on your standard Docker / VM host. Standard setup is $999 one time; you operate the installation.
Custom Kubernetes, Terraform, IAM, SSO, data-lake integration, bespoke connectors and operating services are quoted separately.
Security review depends on network access, credentials and data sensitivity—not contract value. We can walk your team through the architecture, data flow and deployment responsibilities.