01
Central identity
Users authenticate through the central organization login with authorization-code flow, proof-key protection and short-lived application sessions.
Security
VolForge uses the central 42Q Labs identity service, server-side sessions and tenant-scoped data access. The browser never receives market-store, portfolio-system or application trust credentials.
01
Users authenticate through the central organization login with authorization-code flow, proof-key protection and short-lived application sessions.
02
Organization identity is carried through the web boundary, API authorization and every product-state query. Unknown or absent tenant claims fail closed.
03
Viewing analysis, running research, changing portfolios and reading audit history require explicit application roles.
04
The authenticated web application signs a minimal identity envelope for the internal API. Direct proxy headers are rejected.
05
Application, market-data and portfolio-connection credentials remain server-side in protected runtime storage.
06
Imports, calculations, reports and administrative actions produce tenant-scoped audit events without recording access tokens.
Security enquiries and responsible disclosures: [email protected]