Is your platform SEC Reg S-P compliant?
We are not an SEC-registered broker-dealer, investment adviser, financial institution, or funding portal directly regulated under SEC Regulation S-P. However, we maintain administrative, technical, and organizational safeguards designed to protect customer information consistent with the principles of SEC Regulation S-P, including access controls, encryption, secure transmission, monitoring, vendor management, and incident response procedures.
Can you meet the data protection and cyber security reporting requirements related to this rule?
Yes. We maintain administrative, technical, and organizational safeguards designed to support applicable data protection and cybersecurity reporting requirements associated with SEC Regulation S-P and related financial-services security expectations. Our controls include:
Encryption of sensitive data in transit and at rest
Access controls and least-privilege authorization
Enforced MFA
Security monitoring and logging
Vulnerability management and patching processes
Secure software development and change management practices
Vendor and third-party risk management policies and procedures
Incident detection and response procedures
Procedures for security incident notification and customer communication, where applicable
