Ten regimes. Every rule. Every cycle.
The frameworks your licences answer to, encoded once and applied to your live environment continuously, so a breach surfaces as a finding you can contain, not as a letter from the regulator.
Encoded once. Watching always.
Every applicable rule-set runs against your environment automatically, no analyst remembering to check before an audit.
Where the regimes diverge, the detail is per regulator:
The rules that become reportable breaches.
- Leverage & margin caps
- Negative balance protection
- Margin close-out rules
- Pricing & best execution
- Marketing & risk-warning flags
- Breach-clock awareness
The moment a breach exists, a clock starts.
Under every major framework, a material breach you discover must be self-reported inside a fixed window. The obligation isn't optional. The only variable is timing.
Find it first and you report it identified, contained, remediated. Find it second and you're explaining months of undetected client impact to someone who already knows the answer.
- Findings timestamped from first detection
- Severity-ranked so the reportable ones surface first
- A defensible record of when you knew and what you did
- Continuous, not a 90-day-blind quarterly audit
Compliance, answered plainly.
No. It's the platform your compliance team has never had, continuous, server-side surveillance that surfaces issues for them to act on. We find it; your team decides and reports.
Your vendor reports on its own platform and has every incentive to show it working. We sit outside it, read-only, and our only job is to find what drifted, including things a vendor wouldn't flag.
Every applicable rule-set runs in parallel against the relevant books and groups. A single environment can be checked against ASIC, FCA, CySEC and more in the same cycle.
Yes. Every finding is timestamped from first detection and retained as a tamper-evident record, the defensible trail you want when a regulator asks how a breach was handled.
Ten regimes. Every rule. Every cycle.
The frameworks your licences answer to, encoded once and applied to your live environment continuously, so a breach surfaces as a finding you can contain, not as a letter from the regulator.
Encoded once. Watching always.
Whether you hold one licence or ten, every applicable rule-set runs against your environment automatically, no analyst remembering to check before an audit.
Where the regimes diverge, the detail is per regulator.
ASIC
Caps by asset class, the seven-currency major-pair list, and the hedged-margin rule no European regime has.
FCA
Crypto is prohibited for retail rather than capped, so no leverage setting makes it compliant. Government bonds run at 30:1.
ESMA
European measures, national licences. Government bonds at 5:1, and AUD pairs that do not count as majors.
CySEC
European caps beside an offshore book at 200:1, sharing symbol names and the same operations team.
The rules that become reportable breaches.
Every applicable regime is applied to your live environment automatically. These are the checks. How we detect each one is walked through against your own environment.
Leverage & margin caps
Every symbol group checked against the leverage and margin limits mandated for retail clients in each jurisdiction you hold a licence in.
Negative balance protection
Confirmation that NBP is enforced where required, and an alert the moment a group configuration would let a client go below zero.
Margin close-out rules
Continuous validation of stop-out levels against the regulatory floor, per group, per server.
Pricing & best execution
Surveillance for quotes, spreads and execution behaviour that would breach fair-pricing and best-execution obligations.
Marketing & risk-warning flags
Configuration signals that intersect with marketing restrictions and mandated client risk disclosures.
Breach-clock awareness
Findings are timestamped from the moment they appear, so you know exactly where you stand against each regime's reporting window.
The moment a breach exists, a clock starts.
Under every major framework, a material breach you discover must be self-reported inside a fixed window. The obligation isn't optional. The only variable is timing.
Find it first and you report it identified, contained, remediated (a brokerage in control). Find it second and you're explaining months of undetected client impact to someone who already knows the answer.
- Findings timestamped from first detection
- Severity-ranked so the reportable ones surface first
- A defensible record of when you knew and what you did
- Continuous, not a 90-day-blind quarterly audit
Compliance, answered plainly.
No. It’s the platform your compliance team has never had, continuous, server-side surveillance that surfaces issues for them to act on. We find it; your team decides and reports.
Your vendor reports on its own platform and has every incentive to show it working. We sit outside it, read-only, and our only job is to find what drifted, including things a vendor wouldn’t flag.
Every applicable rule-set runs in parallel against the relevant books and groups. A single environment can be checked against ASIC, FCA, CySEC and more in the same cycle.
Yes. Every finding is timestamped from first detection and retained as a tamper-evident record, the defensible trail you want when a regulator asks how a breach was handled.