Security FAQ
Security and compliance handbook for bank-owned deployments.
Overview
The Security & Compliance Handbook is the definitive guide for technical auditors and security teams.
It provides a deep dive into the platform's security architecture. This includes row-level permissions, SOC-2 adherence, multi-cloud deployment across AWS, GCP, and Azure, data residency, and private tenancy.
Use this handbook to confidently integrate Uptiq within highly regulated environments.
Security posture
Building fast shouldn't mean looking over your shoulder. At Qore, we believe that sovereignty is the ultimate feature.
That’s why we’ve engineered a "Fortress-First" architecture that places the entire AI runtime and transactional database directly inside your bank’s own cloud infrastructure.
We don’t just "support" security; we give you total ownership of it.
From AES-256 encryption at rest to automated PII masking that redacts sensitive data before it even hits a model, every layer of our platform is designed to pass the most rigorous technical audits with flying colors.
The following FAQ provides the "under-the-hood" details your CTO and compliance teams need to verify that in the Uptiq ecosystem, your data never leaves your perimeter.
Frequently asked questions
A. Deployment Architecture & Data Residency
B. Access Control & Authentication
C. Data Protection & Encryption
D. Model & Runtime Security
E. Monitoring, Logging, and Auditability
Retention policy
This standard policy covers document and database storage in North America.
Document storage
Storage types: S3, File Store, and DMS
Customer / Loan Documents
7 years post account closure
Aligns with FFIEC, OCC, SEC Rule 17a-4, CRA, and IRS recordkeeping
Use Object Lock (Compliance Mode) or immutable storage; configure lifecycle to move to Glacier after 1 year, delete after 7 years
Operational / System Logs (non-audit)
1–2 years
Forensics & troubleshooting
Store in standard S3 class or log archive bucket with lifecycle deletion after 2 years
Audit Logs/Security Events
7–10 years
Regulatory and internal governance (SOX, GLBA)
Immutable (WORM) storage with Object Lock; retention rule = 7-10 years
Temporary Uploads/Draft Attachments
30-90 days
Data minimization and cleanup
Auto-delete after retention period using lifecycle or scheduler
Database storage
Database types: RDS, MongoDB, and PostgreSQL
Core transactional data
7 years after relationship closure
IRS, OCC, FDIC, and Sarbanes–Oxley Act requirements
Partition or archive tables; automate purge post- retention
User accounts / authentication records
Active + 1 year post-deactivation
Privacy and accountability
Soft-delete with periodic cleanup job
Model input/ output logs (AI/ analytics)
6–12 months (operational)
Data minimization under GDPR/CCPA principles
Store in separate schema or S3; purge automatically after retention period
Configuration/metadata
Until decommissioning
Required for reproducibility
Retain until system decommissioning or replacement
Last updated

