Security is the foundation of everything we build. Here's exactly how Qubix protects your funds, your data, and your investments — at every layer.
Every page on Qubix is served over HTTPS with TLS 1.2+ encryption, so data moving between your browser and our servers can't be intercepted or read in transit. Sensitive fields — passwords, API credentials, and wallet keys — are hashed or encrypted at rest using industry-standard algorithms, never stored in plain text.
Our infrastructure runs on access-controlled servers with restricted internal permissions. Engineers don't have blanket access to user funds or production databases — access is logged, scoped, and reviewed.
Different asset classes carry different custody models. Here's how each is held and protected:
If you discover a security vulnerability on Qubix, we want to hear from it before anyone else does. Email security@qubix.io with a clear description and reproduction steps. Please avoid testing in ways that could affect other users' accounts or funds.
We aim to acknowledge all reports within 2 hours and will keep you updated as we investigate and resolve the issue. Researchers who responsibly disclose valid vulnerabilities may be eligible for recognition or a reward, assessed case by case.