Governance & Controls

Controls exist so that the people responsible for stewardship can demonstrate exactly what happened, when, and under whose authority.

Dual Control

High-impact actions — capital movements, KYC overrides, bulk exports, and configuration changes — require maker-checker approval. No single individual can complete these actions alone.

Hardware MFA

Access to the Admin Control Plane requires hardware security keys (WebAuthn / FIDO2). Privileged actions demand step-up authentication with device-bound credentials.

Role-Based Access

Permissions follow a strict hierarchy: viewer → ops → compliance → investor relations → trader → super-admin. Each role is limited to the minimum necessary authority.

Immutable Audit Trail

Every sensitive view and every administrative action is recorded in a hash-chained audit log suitable for internal review and external examination.

Investor-Facing Assurances

Asset Segregation Client assets remain in dedicated ranges. Firm capital is never co-mingled.
Control Plane Isolation Staff access is fully separated from the investor-facing application.
AI Boundaries AI may explain activity. It cannot move capital or change account state.
No Silent Changes All material actions require explicit human confirmation through controlled paths.

Admin Control Plane Isolation

The Admin Control Plane operates on independent identity, network, and infrastructure. It never shares secrets or runtime with the client-facing application.

Admin Control Plane isolation diagram

Questions about our control environment?

We are prepared to discuss governance design with principals and authorized representatives.

Begin a Confidential Conversation