Security & compliance

Built to survive a due-diligence questionnaire

You are trusting us with proprietary research and client portfolio data. This page sets out exactly how that data is protected, where it lives, who can reach it, and where our audits currently stand — including what is still in progress.

Data privacy

  • Encryption at rest and in transit
  • Role-based access controls, least privilege by default
  • Secure SSO integration
  • Documented backup and disaster recovery
  • Isolated VPCs separating environments

Compliance

  • SOC 2 Type II audit in progress
  • GDPR-aligned privacy practices
  • Industry-aligned data retention policies
  • Data sovereignty via in-region cloud hosting where required

Observability

  • 24/7 monitoring and alerting
  • Full audit logs across systems and data access
  • High-availability architecture
  • Documented incident response and recovery

Audit status

Where our SOC 2 Type II audit stands today

Our SOC 2 Type II audit is in progress. Until the report is issued we do not describe ourselves as certified, and we do not display the AICPA or auditor marks. We would rather you learn our exact position here than discover it during diligence.

The controls the audit examines are already operating: encryption, least-privilege access, SSO, audit logging, monitoring, backup and recovery, and documented incident response. Our Trust Center carries the current control set, policies and status, and we are glad to walk your operations or compliance team through any of it directly — including subprocessors and data flows.

Data integrity is a security concern

In systematic investing, a silent data error is indistinguishable from a security failure: both produce decisions you cannot defend. Our market data comes through our Morningstar partnership, mapped, adjusted and reconciled daily, with point-in-time histories and controls that mitigate survivorship and look-ahead bias.

The practical consequence is that a backtest and a live rebalance read the same datasets — so what you validate is what you trade, and what you report to a client can be reproduced months later.

See the data foundation

Who you are contracting with

BIASafe operates as a group. BIASafe Inc. (Montréal) provides the technology platform. BIASafe Securities USA Corporation (New York) is registered with the U.S. Securities and Exchange Commission, CRD No. 342777. BIASafe EMEA s.a.r.l. operates from Casablanca Finance City.

Which entity you contract with, and the services in scope, are set out in our Form CRS and Form ADV.

Read our Form CRS

Your strategies remain yours

The factors you define, the rules you write and the research you produce on the platform are your intellectual property. We provide the infrastructure; we do not take a claim on your alpha, and we do not use your proprietary strategy configurations to build our own. The governing terms are set out in writing.

Read the terms

Bring us your security questionnaire.

We would rather answer it in detail now than surprise you later.

Book a Demo »