Quaestor
Quaestor is Hartsec's primary Financial Transaction Manager - a reconciled, auditable ledger for every payment your product touches. We support access to a managed public node that offers tiers restricted by requests per second or dedicated managed nodes that offer no restrictions.
Additionally, Hartsec offers integrations into a number of services for your needs, such as game servers or sites communicating over TCP. If we don't presently offer an integration into a publicly available service, contact us and we can make one for you. Alternatively, Hartsec is able to create an integration into your back-end service on demand.
Using Quaestor, you're provided with the following guarantees for every financial transaction:
Prevention of any and all race conditions that may occur during transactions for multi-node instances
Full ACID compliance so that your request is guaranteed to complete successfully or not at all.
ACID - Atomicity, Consistency, Isolation and Durability , represents a method of performing database transactions. These guarantee that a transaction will either complete successfully or will fail without persisting any partial sets of data - e.g. a debit without a credit.
Quaestor is generally split into two separate tiers:
Public Nodes - access to Hartsec's public instances of Quaestor located in different regions around the world
Managed Instances - instances of Quaestor that are hosted on your hardware but managed and monitored by Hartsec personnel
Public nodes are cheaper but provide less guarantees as to performance.
Auditability
Quaestor was designed with auditability in mind, akin to the historical elected officials of Quaestors of the Roman Republic - representing individuals who were charged with supervising the state treasury, and conducting audits or prosecuting capital cases in trials. If an incident occurs and Quaestor is unable to identify it and react accordingly, then Quaestor is failing.
To prevent this, every transaction tracks a number of details relating to it - this ranges from the obvious relevant accounts, to the channel that we received this transaction request through and the related branch. These details are easily accessible through the Quaestor CCI, can be directly exported to CSV or can otherwise be pulled down via Account Statements.
Integrity
Quaestor prioritises Integrity above performance and efficiency, rather than an added side-bonus. All transactional requests are performed with an Idempotency Key to verify that this is the first time that this request has been submitted. If we receive a request with a duplicate, we return the response provided for that particular request.
Additionally, thanks to our ACID-compliance, every request that receives a positive response can be guaranteed to have been completed in its entirety and without issue. To confirm this, every transaction goes through two series of checks - one during the initial transaction request, and again, when we move the transaction from PENDING to COMPLETED, where we verify the details once more and confirm that it is legitimate. Any transaction that does not pass the initial check does not receive a positive confirmation in the request - any that does not pass the second is automatically marked for fraud.
We verify every incoming request against a stored API key and IP address origin. If either do not match, we do not process the request.
To aid in our mission to maintain integrity, Quaestor has full support for business rules. If a transaction is performed that falls outside the bounds of these rules that you define, we reject it.
We support business rules of the following types:
Daily (total dollar value over the last 24 hour period)
Weekly (total dollar value over the last 7 day period)
Monthly (total dollar value over the last monthly period)
Yearly (total dollar value over the last 12 month period)
Transaction (dollar value of the transaction)
Balance (the balance of the sender or the recipient, as defined by the rule)
Count Daily (total number of transactions over the last 24 hour period)
Count Weekly (total number of transactions over the last 7 day period)
Count Monthly (total number of transactions over the last monthly period)
Count Yearly (total number of transactions over the last 12 month period)
Count Global (total number of transactions since account creation)
All of the above rules support minimum and maximum values, and support referencing either the sender or the recipient of the transaction. Customisation of these limits can be done via the Quaestor CCI, or they can otherwise be configured on request by Hartsec support. These limits ensure that any rules that your business wants to set can be established, and your financial security maintained.
NOTE: Proper configuration of Quaestor's business rules can effectively make your environment completely secure from financial incidents. Mis-configuration can, at best, prevent valid customers from performing transactions or, at worst, prevent blocking of financial incidents. Hartsec support are here to assist if you require aid in setting up these settings.
Multi-Bank
Quaestor can support multiple clients and economies on a single instance. Every "bank" (representing back-end client) operates on their own economy, own account blocks, and operate in total isolation from other clients. Cross-currency transactions can occur with the right extension, and can operate with approved exchange rates so that economies with different levels of inflation can still work with one another without concern and without integrating external applications.
Exchange transactions can result in unexpected behaviour if not performed properly and as such rates should be carefully monitored. Hartsec can perform this for you as part of our offerings for our Exchange Transaction extensions.
Efficiency
While Quaestor puts an emphasis on the integrity and auditability of its' offerings, we can still offer high levels of efficiency for your transactional purposes. Quaestor utilises caching to improve the general efficiency and speed of all requests - balance enquiries operate on cached results, and as such often results in sub-millisecond response times. Transactions aim for <50 millisecond response times, but this can grow during times of increased load.
Under testing conditions with a constrained MariaDB database, Quaestor was able to perform ~3,400 transactions per second. Quaestor is fully capable of both horizontal and vertical scaling, and as such greater transaction speeds are expected with improved resource allocation.
Quaestor supports both MariaDB and PostgreSQL - meaning it can integrate into your preferred database administration pipeline with relative ease.
It's highly recommended that use of caching software such as Valkey or Redis is used alongside Quaestor to improve response times. This will be configured as part of your license on purchase of a Managed Node license of Quaestor.
Integrations
Hartsec offers dedicated integrations into existing publicly-available services online. Upon purchase, we offer guides and our own configurations for you to manage these configurations and attach them into your chosen Quaestor node.
Have an integration that you'd like but we presently don't offer? Get in touch with us and we may be able to make it for free ahead of your purchase of a Quaestor license!
All of our integrations support all of our Financial Transaction Managers. Your specific service may not necessarily be suitable for Quaestor depending on your requirements - feel free to contact us to confirm if Quaestor is suitable for you.
You may be interested in one of our more popular integrations, the Minecraft Integration. Contact us to purchase these two in a bundle.
Change Requests
Have a new feature that you would like to make this perfect for your environment? Certain tiers of Quaestor allow you to request a free small Change Request, meaning that you request it and we'll make sure that our integration works for you. Even if you're not on one of these tiers (or the CR is not small), contact us and we may be able to make it happen anyway, and we'll provide you with a quote.
All change requests are subject to approval by project management. Your free request may not necessarily be approved by Hartsec - a quote to complete the work will be offered in this case.
Hartsec may decide to make your change request available as a general offering to our other customers. This will be factored in when you are provided with a quote.
NOTE: Quaestor is NOT PCI-DSS compliant, and cannot interact directly with external banking software. Any integrations of that type should be performed via a trusted payment gateway, and only done on private infrastructure (not public).
Hartsec can assist you with creating a payment gateway or otherwise integrating into an existing gateway - contact us for more details!
Public Node - Basic
Up to 10 requests per second
$10 AUD/month
- Provides basic access to a Quaestor public node of your choosing.
- 10 requests per second for all request types (not including balance enquiries)
- Access to support for initial configuration and in the event of any system issues
Public Node - Advanced
Up to 50 requests per second
$30 AUD/month
- Everything that Public Node - Basic offers, plus:
- 50 requests per second for all request types (not including balance enquiries)
- Free access to 1 integration
- Access to Quaestor's API documents for creating your own integration
- Dedicated support personnel for configuration, including for supported integrations
Public Node - Enterprise
Up to 250 requests per second
$150 AUD/month
- Everything that Public Node - Advanced offers, plus:
- 250 requests per second for all request types (not including balance enquiries)
- Dedicated support personnel for performing investigations against potential fraud/malicious activity, as well as recommended remediations
Managed Instance - Single Node
No limit
$1,500 AUD/month
- A dedicated instance of Quaestor on your hardware managed by Hartsec personnel for your exclusive use
- Full access to Hartsec support for issues, performing investigations against potential fraud/malicious activity as well as recommended remediations
- Change Request support for any modifications desired against Quaestor
Managed Instance - Multi Node
No limit
Contact us for pricing
- Everything provided by Managed Instance - Single Node, plus:
- A provided count of instances of Quaestor on your hardware managed by Hartsec personnel for your exclusive use, all operating in a state of horizontal scaling