PanQuest
English
Contact sales

Compliance

Compliance, built into the archive.

Regulators ask the same questions everywhere: can a record be altered, who accessed it, how long is it kept, where is it, and can you leave your vendor. QFX answers each of them in the way the system works.

How QFX supports you

Requirement by requirement.

RequirementHow QFX supports it
ImmutabilityDocuments can be kept on S3 buckets with Object Lock. QFX recognizes Object Lock when a storage location is registered, and the storage itself then refuses to alter or remove a locked object before its retention date, whatever happens upstream.
Audit trailEvery action produces an audit record stating who did what, to which object, when, and with what outcome. Records go to the log, or over HTTP to your own audit or monitoring service.
Access controlUsers sign in through your identity provider. Every operation is governed by permissions, grouped in roles and mapped to your groups, including explicit deny rules and safeguards that keep an administrator from being locked out.
Data residencyQFX runs entirely in your infrastructure. Documents stay on your storage and metadata in your database, in the country and data center you choose. Nothing is sent to PanQuest.
Retention and disposalRetention schedules keep the records of a series for the period your rules require, counted from creation or from a date field, then destroy or transfer them. Legal holds stop deletion and disposition of a series, a collection or a single record until they are lifted. A hard delete removes a record and its stored object, subject to any Object Lock retention.
Exit and portabilityYour documents sit on your own storage and are reachable through a documented, OpenAPI described API. There is no proprietary store to buy your way out of.
Operational resilienceStateless services run as multiple replicas, writes go through a message queue with inspection and replay of failed messages, and every component exposes health checks and metrics.

Regulation

The frameworks our customers work under.

GDPR

Access limited to those who need it, an audit record of every action, exports to answer access and portability requests, a hard delete for erasure requests, and legal holds that keep records needed for a legal claim despite an erasure request.

DORA

For financial entities: an archive that runs in your own infrastructure, a vendor you can exit without a migration crisis, and the logs and metrics your ICT risk management expects.

MiFID II and sector rules

Records kept unaltered for the required period on immutable storage, and produced quickly when a supervisor or client asks.

National archiving law

Long term retention with authentic, traceable records, on storage and in data centers that meet your national requirements.

QFX supports your compliance program; it does not replace it. Your legal and compliance teams decide how each obligation applies to you, and we are glad to work through that with them. Ask us about certifications, audits and our standard security questionnaire answers.

Let us review your archive with you.

Contact sales