Application Controls
- Server-side API key isolation
- httpOnly signed sessions
- CSRF tokens for write APIs
- Origin validation for `squant.ai`
- Rate limits on auth and API routes
- CSP, HSTS, frame, MIME, and permissions headers
squant.ai
AI market controls for serious portfolios
Squant brings secure onboarding, server-side market data, and optimization workflows into one deployable control room for analysis teams.
Optimize AAPL, MSFT, NVDA and QQQ with a 45% max weight.
Private workspace
New users can onboard in seconds. Returning users land directly in the market data and optimization console.
Use Supabase Auth providers. Enable Google and phone sign-in in your Supabase dashboard.
Data is fetched server-side. Browser users never receive provider credentials.