Skip to main content

Security Best Practices

User Access

We recommend that clients implement the following processes to manage access to their environments:

  • Provisioning processes to ensure users granted access to the platform are authorised to do so and are provided with the adequate role and scope.

  • De-provisioning processes, to ensure users who are no longer authorised have their access revoked in a timely fashion.

  • Regular access reviews ensure that there haven’t been any exceptions to the two previous processes, that all accesses are still required (e.g., all users have logged in to the platform in a recent period), and that they remain adequate in terms of privileges and scope.

The privileges granted to each role in the platform are listed in this article.

Sharing Files & Screenshots

In your email correspondence with us, please do not attach confidential information such as entire upload files used in your production environment or passwords. If in doubt, please consult us beforehand.

Additionally, to protect confidential information, please mask sensitive information in screenshots (e.g., ISIN, Quantity held, % holding). Please do not share security identifiers (e.g., instrument names, issuer names) but instead provide us with IDs. These are more specific and do not expose security or asset-level information.

IP Restrictions (Allowed Lists)

If you have decided to apply IP restrictions to your environment, please have an Administrator-designated user let us know about any changes to your production and Disaster Recovery IPs.

Failing to do so could impact the availability of the platform to your users.

Restricted Email Domains

As with IP restrictions, please inform us of any changes to the list of email domains to which your platform should be restricted.

Audit Trail

All actions that modify the application or its users, including data extraction or uploading and changes affecting rule-checking or disclosure processes, are logged to the audit trail (under Admin > Audit Trail).

Users who have been granted Administrator privileges can access this audit trail. In case of abnormal activity in the platform, these users can review or export the audit trails to identify abnormal behaviours.

Audit Trail Streaming

You can stream the audit trail from your environment to your company’s Security Information and Event Management (SIEM).

This feature will allow you to:

  • Monitor security events from your environment in real time;

  • Detect potential security threats as they happen;

  • Enhance your incident response and investigation capabilities.

Authentication Logs Only

For now, only authentication logs will be sent to your platform. The scope will be expanded in the coming months to cover all logs currently visible in your environment's audit trail.

Setting It Up

For instructions on setting up Audit Log Streaming, please refer to this article or contact our Support team.

Third-Party Security Assessment

We've selected the Cloud Security Alliance (CSA) STAR Self-Assessment to convey our current security practices. This questionnaire maps each of its 310 questions to 35 different security standards, including ISO 27001 and SOC 2. You can find our self-assessment on the Cloud Security Alliance website and our Trust Portal.

Furthermore, we hold a SOC 2 Type II Report, which is also available at the above link.

Single Sign-On

We recommend that clients implement Single Sign-on in their environments to enhance security and provide the best user experience for their users.

This article provides instructions for setting up Single Sign-On. If Single Sign-On isn’t a viable option, clients should implement two-factor authentication.

Did this answer your question?