Security & Compliance Roadmap
Current certification status, what exists today, and the sequenced path to SOC 2 Type I.
Current State
No certifications held today. No SOC 2 (Type I or II), no ISO 27001, no external penetration test performed, no external auditor engaged.
What Exists Today
- →A self-authored SOC 2 readiness assessment mapped to the Trust Services Criteria, with gaps explicitly marked
- →Nine adopted security policies (adopted 24 July 2026), plus a SOC 2 program plan and a vendor register
- →Append-only security-event and audit-event streams
- →Access-review evidence export
- →Database-enforced row-level security across the schema
- →AES-256-GCM credential encryption
- →Dual-control approvals
Milestones
July 2027.
July 2027, alongside SOC 2 preparation.
Done — hosted CI runs typecheck, lint, and the full automated test suite (sharded four ways) on every pull request and every push to the main branch, and reports pass/fail on the pull request. Restored 7 August 2026.
Done — branch protection was enabled on the default branch on 7 August 2026. All six checks (typecheck, lint, and four test shards) are required, the branch must be up to date before merging, and the rule applies to administrators as well, so no one can push to or merge into the default branch while a check is failing. Force-pushes and branch deletion are blocked, and linear history is required. Verified by a direct-push attempt, which the server rejected.
Done — the production database is on Supabase Pro, which includes provider-managed automated daily backups with 7-day retention (confirmed by the founder against the live plan tier, 1 August 2026).
Done — the Supabase PITR add-on was enabled by the founder on 6 August 2026 (7-day retention window, roughly two-minute recovery granularity via continuous WAL archival), replacing the daily-backup-only posture.
Done — the nine-policy pack was adopted on 24 July 2026.
Not yet bound; no date committed.
Incident-response formalisation is tied to SOC 2 preparation — closing the gap flagged in the readiness assessment.
Alongside SOC 2 preparation; target July 2027.
Framing
Certification work is deliberately sequenced after first design-partner commitments; the readiness map exists so the gap between today and Type I is known and bounded.
Stated more directly: the platform is built, running in production, and its engineering controls are real and evidenced — read-only market connections, encryption of every stored credential, a mandatory second factor on every account type, ordered authorization in front of every write, an append-only hash-chained financial record anchored into the Bitcoin blockchain, and a registry of never-break rules each tied to a test that runs on every change.
The institutional and professional-service functions around the platform are younger than the platform itself, and we would rather say so than let a diligence process discover it. We are actively building the structure an established firm will properly require. We are not going to present every control function as mature; we are going to be deliberate about building each one correctly, and precise about where each one stands whenever asked. Every open item is named on this page rather than omitted.