Skip to main content

General Compliance Questions

Is your platform SEC Reg S-P compliant?

We are not an SEC-registered broker-dealer, investment adviser, financial institution, or funding portal directly regulated under SEC Regulation S-P. However, we maintain administrative, technical, and organizational safeguards designed to protect customer information consistent with the principles of SEC Regulation S-P, including access controls, encryption, secure transmission, monitoring, vendor management, and incident response procedures.

Can you meet the data protection and cyber security reporting requirements related to this rule?

Yes. We maintain administrative, technical, and organizational safeguards designed to support applicable data protection and cybersecurity reporting requirements associated with SEC Regulation S-P and related financial-services security expectations. Our controls include:

  • Encryption of sensitive data in transit and at rest

  • Access controls and least-privilege authorization

  • Enforced MFA

  • Security monitoring and logging

  • Vulnerability management and patching processes

  • Secure software development and change management practices

  • Vendor and third-party risk management policies and procedures

  • Incident detection and response procedures

  • Procedures for security incident notification and customer communication, where applicable

Did this answer your question?