Trust & compliance

Built for firms that answer to regulators.

The point is not a longer list of acronyms than the next vendor. It is that when your compliance function, your auditor, or a regulator examines the platform — the answers are already there.

Controls

01

Governed by design.

Not a policy document bolted on afterwards — the controls a regulated firm needs are built into how the platform works.

Access & identity

Role-based, audited

Role-based access control with per-tenant administrators. Impersonation is gated and fully audited — every elevated action leaves a record.

Data & encryption

Encrypted, EU-region

Client documents stored encrypted in EU-region object storage, served only through short-lived signed links. Tenant credentials are encrypted at rest with AES-256-GCM and rotated without redeployment.

Documents & signing

ZertES & eIDAS

Document e-signature through a Swiss-regulated provider, compliant with ZertES and eIDAS.

Audit & evidence

An immutable trail

A full audit trail on every record change, plus an immutable, hash-chained audit on strategic portfolio decisions.

Tenant isolation

Isolated per firm

Tenant data isolation at the application layer, with dedicated per-tenant database schemas available on request.

Confidentiality

Client-name code names

Platform-wide client-name confidentiality through a code-name register: staff screens and exports can show firm-assigned code names, with the mapping held in an operations-controlled register and applied by a redaction layer.

Jurisdictions

02

A regulatory model, per firm.

Each tenant carries a regulatory profile matched to where it operates. Four regimes are already modelled.

UK

FCA

Consumer Duty evidence, suitability capture, and conduct controls built into the advisory workflow.

CH

FINMA

Swiss-regulated e-signature (ZertES), cross-border suitability, and documentation standards.

CY

CySEC

MiFID-aligned reporting and record-keeping for Cyprus-domiciled entities.

UAE

ADGM / FSRA

ADGM-aligned profile for firms operating in the Gulf, with data-residency options.

Due-diligence pack

03

The answers, already there.

For a live diligence process, your risk, compliance, and audit functions receive a working evidence pack — not marketing.

Controls summary & data-flow diagram
How data moves through the platform, and the control at each step.
DPA & sub-processor list
Data-processing agreement and the current list of sub-processors.
Sample audit-trail export
A real export showing change history and the hash-chained decision log.
Data-residency statement
Where tenant data lives, with the EU-region hosting model documented.
Tenant-isolation architecture note
How one firm's data is kept separate from another's, at the application and database layer.
Security-test summary
Most recent third-party security testing, summarised.On request, under NDA

“When a regulator examines the platform, the answers are already there — not assembled after the fact.”

Due diligence

Bring your compliance team.

We'll walk your risk, compliance, and audit functions through the controls, the audit trail, and the security & architecture pack. Our security posture is built for regulated wealth, with ISO 27001 on the roadmap and not yet certified.

ir@stellon.com