Security

Secure, compliant financial infrastructure built for enterprise delivery.

RAFT77 products are designed with security, auditability, and operational resilience in mind for regulated financial and enterprise environments. Our security program encompasses people, processes, and technology to protect customer data and maintain trust.

Protective Controls

Core security commitments

Data protection

Encryption in transit and at rest, secure APIs, and strict access controls for customer and market data. All data is encrypted with industry-standard protocols and managed with robust key lifecycle practices.

Operational resilience

24/7 monitoring, incident readiness, automated backup and recovery procedures, and robust deployment practices to keep systems available, secure, and compliant with SLAs.

Compliance-ready delivery

Architecture and development workflows built for regulated finance, auditability, and governance requirements. RAFT77 aligns with SOC 2, ISO 27001, and GDPR frameworks.

Security Framework

Enterprise security pillars

RAFT77 maintains a comprehensive security program organized across eight domains, each with defined controls, processes, and accountability.

Data Protection & Encryption

  • All data encrypted in transit using TLS 1.3 with strong cipher suites
  • Data at rest encrypted with AES-256 using industry-standard key management
  • Strict access controls with role-based permissions and least-privilege principle
  • API authentication via OAuth 2.0 / OIDC with short-lived tokens and PKCE flow
  • Customer data isolated in logical tenant boundaries with encryption at rest

Compliance & Certifications

  • Architecture aligned with SOC 2 Type II trust services criteria
  • GDPR-ready data processing with data processing agreements (DPAs)
  • ISO 27001-aligned information security management system (ISMS)
  • Designed for regulated financial environments with audit-ready controls
  • Regular third-party penetration testing and vulnerability assessments

Identity & Access Management

  • Multi-factor authentication (MFA) enforced for all administrative access
  • Single sign-on (SSO) support via SAML 2.0 and OIDC providers
  • Granular RBAC with segregation of duties across operational roles
  • Automated user access reviews and timely deprovisioning workflows
  • Session management with idle timeout and concurrent session controls

Incident Response & Resilience

  • 24/7 security monitoring with SIEM-driven alerting and correlation
  • Structured incident response plan with defined severity levels and escalation paths
  • Regular tabletop exercises and incident response drills across teams
  • Automated backup and disaster recovery with defined RPO/RTO targets
  • Post-incident analysis with continuous improvement lifecycle

Secure Development Lifecycle

  • Security requirements embedded in all product development phases
  • Automated SAST/DAST scanning in CI/CD pipeline for every deployment
  • Third-party dependency scanning with automated vulnerability alerts
  • Peer-reviewed code changes with security checkpoints before merge
  • Regular security training and awareness programs for engineering teams

Vendor & Third-Party Security

  • Security assessments for all third-party integrations and vendors
  • Data processing agreements with contractual security obligations
  • Continuous monitoring of vendor security posture and compliance status
  • Limited data sharing with strict contractual controls
  • Regular review of vendor access and data handling practices

Infrastructure Security

  • Cloud infrastructure secured with network segmentation and WAF
  • Host-level hardening with CIS benchmark alignment
  • Container security with image scanning, runtime protection, and least-privilege
  • Immutable deployment patterns reducing configuration drift risks
  • End-to-end audit logging for all infrastructure and application events

Customer Trust & Transparency

  • Transparent security documentation and shared responsibility model
  • Customer data portability with structured export capabilities
  • Clear data retention and deletion policies aligned with customer requirements
  • Dedicated security contact for customer vulnerability disclosures
  • Regular security posture reporting and compliance attestations available on request
Shared Responsibility

How we work with customers on security

Security assessments

We provide security documentation, architecture overviews, and control evidence to support customer security and compliance teams in their assessment processes.

Compliance briefings

Schedule dedicated briefings with our security team to review controls, certifications, and data handling practices aligned to your regulatory requirements.

Vulnerability disclosure

RAFT77 maintains a responsible disclosure program. Security researchers and customers can report potential issues to our dedicated security team for prompt triage and remediation.

Security engagement

Talk to us about security requirements

Reach out for security assessments, compliance briefings, penetration testing results, and details about how RAFT77 applies controls across product delivery and integration. Our security team is ready to support your evaluation.