Security and records
Built for the records rules broker-dealers live under. Here's what we do, in plain terms, and the documents your vendor review will ask for.
Two-factor sign-in for everyone
Required for every account, or single sign-on through your identity provider. Sessions end after 30 minutes idle. Accounts lock after repeated failed attempts.
Each firm's data is walled off
Every query is limited to your firm, and reps and principals only see their own branches. Automated tests try to cross those lines on every change.
Records can't be changed or deleted
Corrections create new versions. The database itself refuses to change or delete past records. The audit log is hash-chained, so any tampering shows.
Write-once storage
Check images and exam packages are stored in Amazon S3 with Object Lock in compliance mode for your retention period (6 years by default). Not even we can delete them early.
Encrypted
In transit with TLS and at rest. Account numbers are encrypted in the database, and only the last 4 digits are ever shown. Image access is logged.
Every access logged
Sign-ins, views, edits, forwarding, reviews, exports and examiner visits are all recorded with who, when and from where.
Vendor due diligence documents
- Security overview
- Data flow diagram
- Subprocessors
- Incident response plan
- Backups and business continuity
- Vulnerability management
- Access control policy
- Security questionnaire answers
- SOC 2 readiness
SOC 2: not yet audited; our readiness plan is linked above. We'll say plainly what is in place and what isn't.