TECHNOLOGY

Control surfaces for every critical system state.

QuantumX separates subscription entitlement, license authorization, deployment health, account connection, software updates, and risk-state enforcement so each can be validated and audited.

AUTH / 01

Signed license authorization

Short-lived tokens bind the permitted MT5 account, broker server, VPS/device, capacity, version, and offline grace period. Revocation and key rotation are first-class operations.

CAPACITY / 02

Allocation boundaries

Effective trading allocation is the lesser of the customer-selected virtual allocation and the licensed capacity. Balance changes never trigger an automatic charge.

SHIP / 03

Signed update pipeline

Agents validate signature and checksum, stage releases, run health checks, defer non-emergency restarts while positions are open, and roll back failed updates.

FAILSAFE / 04

Payment-failure safety

New entries stop after a billing failure. Protective management and exit logic continue for existing positions, with suspension only after the account is flat.

DATA / 05

Market-data integrity

Adapters expose source designation, freshness, stale-feed detection, reconnect state, and update time. The public tape remains visibly in demo mode until a licensed feed is configured.

AUDIT / 06

Least-privilege operations

Role-based access, encrypted sensitive fields, append-oriented audit events, idempotent webhooks, and rate limits constrain administration and automation.

Capacity enforcement without forced full-balance risk

The connected software may read balance or equity only for license capacity, risk controls, status display, and customer notifications. The customer selects a virtual allocation. New entries above the authorized capacity are blocked; existing positions keep protective management. The customer sees an upgrade option and must explicitly approve the Stripe change before new entitlement is provisioned.

Protected deployment is layered

Hiding a file is not a security model. The architecture combines compiled code, protected delivery, account/server/device binding, signed authorization, short expiry, audit logs, rate limits, key rotation, staged updates, and server-side strategy logic where technically feasible.