Home Product Overview
How It Works Governance & Retention Security Framework Architecture & AWS APIs & Portability Use Cases
Resources About QwikARC Contact & Support
Security Architecture

Secure Today
Trust Tomorrow

Historical financial data requires uncompromising security controls. QwikARC enforces a defense-in-depth framework across every layer—ensuring least privilege, immutable audit logging, and hardware-backed secrets management.

Physical Credential Segregation

Right Access
Right Purpose

Prevent privilege escalation. Operational query users never share credentials with administrative maintenance or purge routines.

Daily Inquiries

Read Only

  • ✓ Native MySQL SELECT privileges
  • ✓ Strictly read-only query pool
  • ✓ Zero DDL or DML capabilities
  • ✓ Automated connection timeouts
Catalog Updates

Metadata Write

  • ✓ Updates data dictionary & lineage
  • ✓ Manages retention classifications
  • ✓ Zero access to delete records
  • ✓ Changes logged to audit vault
DBA Superuser

Disposition / Delete

  • ✓ Authority to purge expired records
  • ✓ Restricted to client DBA role
  • ✓ Requires dual-key approval ticket
  • ✓ Complete pre- and post-hash logs
Load Window

Temporary Load

  • ✓ High-throughput migration loader
  • ✓ Time-limited token expiration
  • ✓ Restricted to migration host VPC
  • ✓ Automatically revoked after cutover
Hardware-Backed Security

AWS Secrets Manager &
KMS Integration

No passwords or API tokens are ever hardcoded or stored in application files. All database credentials, encryption certificates, and signing keys are retrieved dynamically from AWS Secrets Manager using IAM role assumption under client-managed KMS encryption keys.