Security

Controls, in detail.

We publish what we actually do, including where the boundaries are. If you need our full control matrix or a pen-test summary, ask your account team.

encryption

In transit and at rest

TLS 1.2+ everywhere, HSTS preloaded. Ledger and PII columns encrypted at rest with per-tenant keys in a managed HSM. Keys rotate every 90 days.

access

Least privilege

Production access is short-lived and brokered — no standing credentials. Every session is recorded and reviewed weekly.

api keys

Key handling

Secrets are shown once at creation and stored only as an Argon2id hash. Scoped per key. Rotation grace-periods the previous secret for 24 hours.

approvals

Dual authorisation

Payouts above your threshold require a second approver with a distinct credential. Approvals are recorded in an append-only audit log.

testing

Independent testing

Annual CREST-accredited penetration test, quarterly internal red-team exercises, continuous dependency and container scanning.

compliance

Assurance

SOC 2 Type II (current report available under NDA), ISO 27001:2022, PCI DSS v4.0 SAQ-D. Safeguarding audited annually.

Reporting a vulnerability

Mail security@aldermoorcapital.online. We acknowledge within one business day and aim to triage within three. We do not currently run a paid bounty, but we credit reporters who ask to be credited. Our PGP key fingerprint is 9F2C 41A0 7DB8 3E15 6C0A 2F91 D447 8B0E 3C21 55AD.