QVL Models

Security & Data Protection

Last updated September 30, 2026

Protecting customer accounts, financial information, and access to QVL is an important part of how we design and operate the QVL platform.

QVL Models, Inc. (“QVL,” “we,” “us,” or “our”) uses technical, administrative, and organizational safeguards designed to protect personal information and reduce unauthorized access to QVL accounts and systems.

This page provides an overview of QVL’s security practices. Additional information about how QVL collects, uses, retains, and discloses personal information is available in our Privacy Policy.

No Internet-connected system can guarantee absolute security. QVL continually evaluates its systems and security controls as the platform evolves.

1. Protecting Information in Transit and at Rest

QVL uses encryption and other security controls designed to protect information based on its sensitivity.

Information transmitted between supported QVL applications and QVL services is protected using secure encrypted connections.

Sensitive information stored within QVL systems is subject to additional safeguards. These may include encryption at rest, protected key management, access controls, authentication requirements, monitoring, and audit logging.

Sensitive connected-account information, including stored brokerage holdings information and provider credentials needed to maintain an authorized connection, is protected using QVL’s secure storage and encryption controls.

QVL limits access to decrypted sensitive information to authorized systems and processes when that information is needed to provide a requested feature.

Examples may include:

  • displaying a connected portfolio;
  • synchronizing authorized holdings;
  • calculating portfolio analytics or risk;
  • preparing or processing an approved brokerage transaction; or
  • supplying authorized portfolio context to QVL Copilot.

QVL does not publish internal encryption keys, security configurations, infrastructure credentials, or other information that could compromise these protections.

2. Password and Account Protection

QVL does not store QVL account passwords in readable form.

Passwords are protected using cryptographic password hashing.

QVL also uses security controls designed to protect account access, which may include:

  • email verification;
  • password requirements;
  • time-limited authenticated sessions;
  • multi-factor authentication;
  • passkeys;
  • authorized-device controls;
  • authentication monitoring; and
  • protections against unauthorized or abnormal access attempts.

Users are responsible for keeping their account credentials secure and should use a unique password that is not reused across other services.

3. Passkeys and Biometric Authentication

QVL supports passkey-based authentication using WebAuthn where available.

A passkey may use security provided by your device or operating system, including:

  • Face ID;
  • Touch ID;
  • fingerprint recognition;
  • Windows Hello;
  • device PINs; or
  • another supported local authentication method.

The biometric verification itself occurs on your device or through your operating-system or passkey provider.

QVL does not receive or store the facial image, fingerprint image, biometric template, or similar biometric information used by your device to authenticate you.

QVL stores cryptographic information necessary to verify the registered passkey, such as the credential identifier and public key.

4. Brokerage Account Security

QVL does not ask you to enter your brokerage password directly into QVL.

When you connect a supported brokerage or investment account, authentication takes place through the applicable brokerage, financial institution, or connection provider.

QVL currently supports connected-account functionality through providers including Plaid and SnapTrade.

Brokerage Credentials

QVL does not receive or store your actual brokerage password.

Instead, after you authorize a connection, QVL may receive a provider-issued credential or access token that allows QVL to perform the activities you authorized.

QVL protects stored provider credentials using encryption and restricted access controls.

Plaid

Plaid is used for supported read-only investment-account and financial-account functionality.

Plaid-connected investment accounts may provide QVL with authorized information such as holdings, balances, account information, and transaction information.

QVL does not use a Plaid read-only connection to place brokerage orders.

SnapTrade

SnapTrade is used for supported brokerage connections and may provide portfolio synchronization and trade-capable functionality where available.

Available functionality depends on the brokerage, account, jurisdiction, and permissions supported by SnapTrade.

5. QVL Does Not Take Custody of Your Brokerage Assets

Connecting a brokerage or investment account to QVL does not transfer custody of your securities or cash to QVL.

Your assets remain with your brokerage or financial institution.

QVL does not obtain general authority through a brokerage connection to withdraw or transfer money out of your brokerage account.

Your brokerage remains responsible for custody of the assets held in the brokerage account.

6. Live Trades Require Explicit User Approval

QVL is designed so that a model signal does not automatically become a live brokerage transaction.

A:

  • QVL model signal;
  • modeled trade;
  • QVL Copilot response;
  • portfolio calculation;
  • notification;
  • alert;
  • staged trade; or
  • background process

does not by itself authorize QVL to submit a live brokerage order.

For supported live brokerage trading, the user must provide the applicable explicit approval before the order is submitted to the broker.

This separation between model generation, trade staging, and live-order approval is an important QVL control.

After an order is submitted, execution is subject to the brokerage and applicable market conditions.

7. Your Brokerage Remains the Source of Truth

QVL may display information received from a connected brokerage account, but the brokerage or financial institution remains the authoritative source for the actual account.

This includes:

  • holdings;
  • positions;
  • cash;
  • balances;
  • buying power;
  • submitted orders;
  • open orders;
  • fills; and
  • account activity.

QVL information may temporarily differ from brokerage records because of synchronization timing, provider availability, market-data timing, or transactions completed outside QVL.

If there is a discrepancy concerning your actual brokerage account, you should rely on your brokerage’s records.

8. Access Controls and Internal Access

QVL restricts access to production systems and sensitive information according to authorization, role, and legitimate business need.

Staff and administrative functionality is separated from ordinary customer functionality.

QVL’s internal tools are designed to limit unnecessary exposure of sensitive brokerage information to personnel who do not require it to perform their function.

Authorized QVL systems may process or decrypt sensitive information when necessary to provide customer-requested functionality.

QVL does not represent that sensitive customer information can never be accessed by authorized personnel or systems. Instead, QVL uses access controls designed to limit such access to appropriate purposes.

9. Security Monitoring, Logging, and Audit Controls

QVL maintains technical logging and monitoring designed to support:

  • authentication security;
  • fraud and abuse detection;
  • service reliability;
  • troubleshooting;
  • security investigations;
  • operational monitoring; and
  • auditability.

QVL applies filtering and redaction controls designed to reduce unnecessary exposure of sensitive information in operational logs and monitoring systems.

Where error-monitoring services are used, QVL configures them to reduce unnecessary personal or brokerage information and applies additional scrubbing controls.

Logging and monitoring information is restricted according to its purpose and sensitivity.

10. QVL Copilot and AI Security

QVL Copilot is designed to operate with controlled access to QVL and customer information.

Simply connecting a brokerage account does not provide Copilot with unrestricted access to all financial-account information.

Where live portfolio information is subject to a permission or consent control, QVL checks the applicable authorization before using that information in Copilot.

When authorized and relevant to a request, selected portfolio information may include information such as:

  • positions;
  • quantities;
  • market values;
  • cost basis;
  • unrealized gains or losses;
  • allocation information;
  • cash;
  • balances; or
  • buying power.

QVL is designed to provide information appropriate to the requested task rather than unrestricted financial-account access.

QVL does not provide Copilot with your brokerage password.

QVL does not intentionally provide brokerage provider access tokens or authentication secrets to Copilot.

QVL currently uses Microsoft Azure AI infrastructure, including Microsoft Foundry and related Azure AI services, to support QVL Copilot.

Copilot remains subject to QVL authorization controls.

A Copilot response cannot independently authorize a live brokerage trade, transfer funds, change account security, connect a brokerage account, cancel a subscription, or delete an account.

Sensitive actions remain subject to their applicable confirmation and authentication requirements.

11. Saved Copilot Chats and Memory

Where supported, QVL may allow customers to save Copilot conversations.

Saved conversations may contain the customer’s visible messages, Copilot’s visible responses, and result information associated with the conversation.

Where Copilot Memory is enabled, QVL may retain selected preferences intended to make future interactions more useful.

QVL’s Memory controls are designed not to intentionally retain information such as:

  • passwords;
  • authentication secrets;
  • provider access tokens;
  • brokerage account numbers;
  • live account balances; or
  • brokerage holdings

as persistent preference memories.

Saved chat history and Copilot Memory are separate features.

Where available, customers may have controls to review, manage, or delete saved conversations or Memory information.

12. Payment Security

QVL uses third-party payment providers, including Stripe, to process supported subscription payments.

Payment-card information is generally entered into a Stripe-hosted or other payment-provider-hosted payment experience.

QVL does not store your full payment-card number or card security code.

QVL may retain payment and subscription information supplied by the payment provider, such as:

  • customer identifiers;
  • subscription identifiers;
  • purchased plan or product;
  • billing status;
  • billing currency;
  • payment status; and
  • invoice information.

Payment providers maintain their own security and privacy practices.

13. Third-Party Infrastructure and Providers

QVL uses specialized service providers to operate portions of the platform.

Depending on the Services used, these may include providers supporting:

  • Microsoft Azure cloud and AI infrastructure;
  • Plaid financial-account connections;
  • SnapTrade brokerage connectivity;
  • Stripe payment processing;
  • transactional email;
  • mobile push notifications;
  • error and security monitoring;
  • market data;
  • research information; and
  • other infrastructure required to provide the Services.

QVL evaluates access to third-party services according to the functions they perform and the information required for those functions.

Third-party services are also subject to their own terms, privacy policies, security practices, and availability.

For more information about how personal information is disclosed to service providers, see the QVL Privacy Policy.

14. Security Incident Response

QVL uses monitoring, audit information, access controls, and operational procedures designed to support the detection and investigation of potential security incidents.

Depending on the circumstances, QVL may take measures such as:

  • investigating unusual activity;
  • restricting access;
  • disabling or revoking credentials;
  • isolating affected functionality;
  • reviewing audit information;
  • correcting affected systems; and
  • coordinating with relevant service providers.

If QVL determines that a security incident requires notification under applicable law, QVL will provide applicable notices in accordance with those requirements.

QVL does not guarantee that every attempted attack, vulnerability, or unauthorized action can be prevented.

15. Protecting Your Own QVL Account

Security is also a shared responsibility.

You can help protect your QVL account by:

  • using a unique password;
  • protecting access to your email account;
  • enabling available multi-factor authentication or passkeys;
  • keeping your device and operating system updated;
  • never sharing authentication codes or credentials;
  • reviewing brokerage confirmations carefully;
  • verifying live orders before approval;
  • signing out of devices you no longer use; and
  • contacting QVL if you notice unexpected account activity.

QVL will not ask you to send your brokerage password by email, chat, or customer-support message.

If you receive a suspicious communication claiming to be from QVL, do not provide account credentials through the communication.

16. Responsible Security Reporting

QVL welcomes responsible reports from customers and security researchers who believe they have identified a potential security issue involving QVL.

Reports should provide sufficient information for QVL to understand and investigate the issue, while avoiding unnecessary access to customer information or disruption of QVL services.

Do not:

  • attempt to access another customer’s information;
  • destroy or modify data;
  • conduct denial-of-service testing;
  • use social engineering against QVL personnel or customers;
  • publicly disclose sensitive customer information; or
  • retain information obtained unintentionally beyond what is necessary to report the issue.

Security concerns should be reported to:

privacy@qvlmodels.com

For privacy-related matters, contact:

privacy@qvlmodels.com

For legal matters:

legal@qvlmodels.com

QVL Models, Inc.
375 University Avenue, Unit 101, Suite 1111
Toronto, Ontario M5G 2J5
Canada

17. Security Practices Continue to Evolve

Security practices change as technology, threats, QVL products, and regulatory requirements evolve.

QVL may update this page periodically to reflect material changes to its security practices or available security features.

The publication of this page does not create a guarantee that unauthorized access, data loss, service disruption, or another security event can never occur.

For information about QVL’s handling of personal information, please review the Privacy Policy.

For the contractual terms governing use of QVL, please review the Terms of Service.

For financial-market and trading risks, please review the Risk Disclosure.