Security / Trust center

Security is the product.

Qentra products are designed around isolation, least privilege and verifiable control—not promises hidden behind a simple interface.

01

Architecture

Marketplace plugins are intentionally thin clients. Proprietary policy logic, platform credentials and AI provider secrets stay in the Qentra control plane. Clients receive short-lived, tenant-scoped authorization and only the data required for the immediate operation.

02

Tenant isolation

Every request is bound to an authenticated tenant and checked again at the data boundary. Data stores, encryption contexts, object identifiers and rate limits are tenant-aware. Administrative actions require stronger authorization and are written to an append-only audit log.

03

Secrets

Secrets are never shipped inside public plugin packages or returned to browsers. Production credentials are held by the deployment platform, encrypted at rest, rotated, redacted from logs and separated by environment.

04

Secure delivery

Releases are built from reviewed source, checked for vulnerable dependencies, signed where the target marketplace supports it and promoted through isolated environments. Production access follows least privilege and is recorded.

05

Responsible disclosure

If you believe you found a security issue, email security@qentra.tech. Include the affected product, impact and reproducible steps. Please avoid accessing other users’ data or disrupting service. We will acknowledge valid reports and coordinate remediation in good faith.