VolForgeSign in

Access is explicit. Tenant boundaries are enforced.

VolForge uses the central 42Q Labs identity service, server-side sessions and tenant-scoped data access. The browser never receives market-store, portfolio-system or application trust credentials.

01

Central identity

Users authenticate through the central organization login with authorization-code flow, proof-key protection and short-lived application sessions.

02

Tenant isolation

Organization identity is carried through the web boundary, API authorization and every product-state query. Unknown or absent tenant claims fail closed.

03

Role-based actions

Viewing analysis, running research, changing portfolios and reading audit history require explicit application roles.

04

Server-side trust

The authenticated web application signs a minimal identity envelope for the internal API. Direct proxy headers are rejected.

05

Restricted secrets

Application, market-data and portfolio-connection credentials remain server-side in protected runtime storage.

06

Auditability

Imports, calculations, reports and administrative actions produce tenant-scoped audit events without recording access tokens.

Security enquiries and responsible disclosures: [email protected]