Skip to main content
Security & Compliance

Built for the people who hold the book

Your trade data, your clients’ data and your platform are the most sensitive things you own. Finnovic is built to touch them with least privilege, log every change, and stay out of the way of trading.

Architecture

Connected carefully — never in the way

Finnovic integrates with MetaTrader through its Manager and Web API, not by injecting code into your trading server.

API-based integration

We connect via the MetaTrader 5 (MT5) Manager / Web API — no third-party plugins forced into your trade server.

Least privilege

Credentials are scoped to exactly what a feature needs — read-first, with writes limited to the task.

Verified writes

Where we do write — hedge orders, swap reversals — the result is read back from MT5 to confirm it landed, and logged.

Resilient connection

The live data link fails over automatically (Manager pump → Web API) and recovers without manual intervention.

Your data

Your book stays in your environment

Finnovic deploys on infrastructure you control, or runs as a managed service on isolated infrastructure we operate for you — your call.

  • Data residency — trade and client data stay in your chosen environment.
  • Encrypted credentials — MT5 and LP secrets are stored encrypted, never in plain text.
  • Backups & recovery — scheduled backups with tested restore procedures and a clear DR plan.
  • Data retention — configurable retention windows for logs and records.
  • Patching & hardening — OS and platform patching, firewall and DDoS protection on managed deployments.

On your infra

Self-host on your servers; we integrate over the API.

Managed by us

Isolated infrastructure we provision, patch and monitor continuously.

Encrypted

Secrets at rest encrypted; access on a need-to-use basis.

Recoverable

Backups tested with documented restore steps.

Access & accountability

Every change is an attributable decision

Role-based access

Granular, per-action permissions so each person sees and does only what their role allows.

2FA & session security

Optional two-factor authentication, protected sessions, brute-force lockout and rate limiting on sign-in.

Full audit trail

Every plan edit, swap change, hedge, bulk job and login is logged, attributable and exportable.

Data isolation

IB- and branch-scoped filtering keeps each team’s view limited to its own sub-tree.

Reconciliation

Independent cross-checks (e.g. swap-free Cross-Verify) reconcile our records against MT5 to the cent.

Monitoring & alerts

Health checks, drift detection and alerting flag issues before they reach your clients.

Compliance posture

What we can show your compliance team

AreaDetail
Data protectionGDPR-aligned handling; privacy policy published; Data Processing Agreement (DPA) available on request
KYC / AMLFinnovic Hub provides KYC workflow, document handling, risk rating and PEP/AML flags
Sharia complianceFinnovic Flow swap-free engine — true net-zero reversal with an explainable reason code for every action
Access controlRole-based access, optional two-factor, session security, full audit trail
ResilienceBackups + tested recovery; automatic MT5 connection failover
Due diligenceSecurity overview, architecture notes and DPA shared under NDA — request the pack

Need the due-diligence pack?

Tell us what your compliance or IT team needs to see and we’ll share our security overview, architecture notes and DPA under NDA.

Request the pack →