Security
How QubTrading protects your data, accounts, and transactions.
Data Encryption
Your data is protected with industry-leading encryption at every layer:
- All data encrypted in transit with TLS 1.3, the latest transport layer security protocol
- HTTPS enforced via HSTS with 1-year preload, preventing downgrade attacks
- Passwords hashed using bcrypt with salting — never stored in plain text
TLS 1.3 HSTS Preload bcrypt Hashing
Payment Security
Your financial information is handled with the highest security standards:
- Payments processed by Stripe, a PCI Level 1 certified payment processor (the highest certification level)
- Credit card data never touches QubTrading servers — all payment information is handled directly by Stripe
- 256-bit SSL encryption on all payment transactions
Stripe PCI Level 1 256-bit SSL
Account Protection
Multiple layers of defense protect your QubTrading account:
- Cloudflare Turnstile CAPTCHA on login and signup to prevent automated attacks
- Rate limiting on login attempts — 5 failed attempts triggers a 15-minute lockout
- OTP email verification for sensitive account actions
- Automatic session management with secure token handling and expiration
Turnstile CAPTCHA Rate Limiting OTP Verification
Infrastructure Security
Our infrastructure is built on trusted, certified platforms:
- Hosted on Netlify (SOC 2 Type II certified) with global CDN distribution
- Database on Supabase (SOC 2 Type II certified, encrypted at rest with AES-256)
- Content Security Policy (CSP) headers to prevent code injection attacks
- Protection against clickjacking via X-Frame-Options headers
- Protection against XSS (Cross-Site Scripting) via X-XSS-Protection and CSP
- Protection against MIME sniffing via X-Content-Type-Options headers
- Cross-Origin policies enforced (CORS, COEP, COOP) to isolate browsing context
SOC 2 Type II AES-256 at Rest CSP Headers
Responsible Disclosure
If you discover a security vulnerability, please report it to admin@qubtrading.com. We appreciate responsible disclosure and will work with you to understand and address the issue promptly.
Please do not publicly disclose the vulnerability until we have had an opportunity to investigate and deploy a fix. We are committed to responding to all security reports within 48 hours.
Last updated: March 17, 2026