Security
The controls below are implemented and covered by automated tests that run on every change.
Authentication
Sessions are held in cookies that browser script cannot read. Privileged roles carry a second factor, and a used code cannot be replayed. Sign-in attempts are rate limited per address and per identity.
Authorisation
Every request is re-checked against the caller's current role. Hiding a control in the interface is a courtesy; the refusal happens at the platform.
Tenant isolation
Enforced in the database with row-level security, not only in application code. The runtime database role holds no privilege that would let it read another institution's rows.
Financial invariants
Balanced entries, append-only ledgers and immutable quote pricing are enforced by database constraints and triggers, so a defect in application code cannot produce an unbalanced book.
Separation of duties
Sensitive operations require a second approver, and self-approval is refused. The policy that applied is snapshotted, so a later edit cannot rewrite what was in force.
Audit
Every state transition is recorded with its actor, reason and payload, append-only. A conversion can be reconstructed end to end from the record alone.
Provider failure
An unavailable provider is never treated as a clean result. A screening outage holds the transaction; an unknown execution is never retried into a success.
Keys
The platform holds no virtual asset private key. There is no production signer, and custody is disabled and cannot be enabled in production.
What we do not claim
- An automated test suite is not a penetration test. It proves the controls we designed operate as designed.
- No software prevents a malicious insider or a compromised administrator. Ours makes their actions visible and reconstructable, and separates duties so that one person acting alone is constrained.
- Settlement on a public network is subject to that network. We follow a transfer to an agreed confirmation depth and report a reorganisation rather than ignoring it.
Due diligence
We maintain a threat model with residual risk stated per threat, documented trust boundaries, operational runbooks, and an evidence index mapping each regulatory area to its implementation, its tests and its outstanding confirmations. These are provided to institutional counterparties under diligence.