Security
Controls,
stated plainly.
No badge wall, no vague assurances. What is actually in place today, what the journal architecture gives you, and how to reach us about a problem.
Posture, plainly
We are a small infrastructure company in build-out, and this page says what is true today — not what a compliance page template wishes were true. It will grow as the controls grow.
Transport and connectivity
- All web traffic to this site and to bridge management surfaces is encrypted in transit (TLS).
- LP FIX sessions run over the counterparty's prescribed secure transport — dedicated lines or VPN/TLS per the LP's connectivity standard — negotiated during certification.
- Bridge components talk to each other on private networks; nothing in the order path listens on the open internet.
Access
- Least access by default: production access is limited to the operators who run the system, individually identified — no shared accounts.
- Administrative actions on the bridge are authenticated, attributed and recorded in the same journal that records order flow.
The journal as a control
The bridge's core design decision doubles as its strongest control: every order-lifecycle event and every policy change is written to a durable, append-only journal before it takes effect. There is no unrecorded action. For a desk, that means any question — operational, compliance, or forensic — resolves to a query, not an investigation.
Data
- The bridge processes order, position and account data your platform already holds; we treat all of it as confidential client data under the services agreement.
- This website collects nothing beyond the request-access form (see the privacy notice) and sets no tracking cookies.
Certifications
We do not currently hold SOC 2 or ISO 27001 certification, and we won't imply otherwise with an "in progress" badge until an audit engagement actually exists. Counterparty security questionnaires are answered directly and honestly during onboarding.
Reporting
If you believe you've found a security issue in anything we run, write to access@mmsys.xyz with "SECURITY" in the subject. Reports are read by the operators, not a queue.