Security for financial order infrastructure

Portfolwright processes order sequencing instructions on behalf of retail investment platforms. Encryption, access controls, audit logging, and EU data residency are not features — they are requirements. This page describes exactly what controls are in place and, equally important, what we do not yet claim.

Security controls

What we do to protect your data and your customers’ orders

Encryption in transit and at rest

All API traffic uses TLS 1.2+ with strong cipher suites. Data at rest encrypted using AES-256. API keys stored as bcrypt hashes — we cannot read your keys after issuance, only verify them. Database backups encrypted with a separate key.

Access control via OAuth 2.0 and scoped API keys

API keys are scoped to minimum required permissions: read-only keys for dashboards, write keys for order submission, admin keys (your exclusive use) for account management. OAuth 2.0 client credentials flow available for service-to-service authentication. No shared credentials.

Audit logging

Every API call, order submission, rebalancing event, and MiFID II record generation is logged with timestamp, API key identifier, IP address, and request ID. Audit logs are immutable and retained for 5 years. Exportable on request — your compliance team gets exactly the evidence they need.

EU data residency

All customer data — portfolio records, order history, tax lot data, MiFID II records — is stored in EU data centers. We do not transfer personal data outside the EEA without an appropriate GDPR transfer mechanism. Data Processing Addendum available on request.

Compliance posture

What we can and cannot claim

What we do

  • MiFID II Article 25 record-keeping (technically required for our service)
  • GDPR-compliant data processing with DPA available
  • EU data residency by default
  • TLS 1.2+ and AES-256 encryption
  • Immutable 5-year audit logs

What we don’t claim

  • SOC 2 Type II (we are pursuing this; audit not yet complete)
  • ISO 27001 certification (in planning)
  • PCI DSS (we don’t process payment cards)

We are transparent about certification status. If your procurement requires SOC 2, contact us about timeline and interim controls evidence.

Request a DPA or security documentation