Security

Infrastructure Security Designed for Institutional Trading

End-to-end encryption in transit and at rest, strict role-based access controls, immutable audit trails, and physical security standards that meet institutional risk requirements.

Security architecture layers and access control diagram
Encryption

Data Protection at Every Layer

Encryption in Transit

All management API traffic uses TLS 1.3 with AEAD cipher suites. Connection establishment enforces forward secrecy. Internal service-to-service traffic within the co-location environment uses mutual TLS (mTLS) with client certificate pinning.

Encryption at Rest

All stored data including configuration, credentials, API keys, and historical trade records is encrypted using AES-256-GCM. Encryption keys are managed in a dedicated HSM. Key rotation is automatic on a 90-day schedule.

Key Management

API keys are issued per integration endpoint with configurable IP CIDR restrictions. Keys are never stored in plaintext. HMAC-SHA256 request signing is available as an additional authentication layer for order submission.

Order Data Isolation

Order flow, fill records, and routing decisions are stored in per-client isolated namespaces. No shared memory, shared buffers, or shared queues between client environments. Cross-client data access is architecturally impossible.

Access Controls

Role-Based Access for Every Team Member

Fine-Grained RBAC

Roles are defined at the action and resource level: read-only access to historical fills, write access to specific symbol lists, admin access to integration configuration. Permissions are additive; no role inherits another by default.

SSO and MFA

Management console supports SAML 2.0 and OIDC SSO. All human access to the management console requires multi-factor authentication. TOTP and hardware security key (WebAuthn) both supported.

Immutable Audit Log

All access to configuration, order management, and account settings is logged to an append-only audit store. Log entries include actor identity, IP address, timestamp, and full request payload. Logs are exported to your SIEM on request.

Anomaly Alerts

Configurable alerts on unusual access patterns: off-hours login from a new IP, API key usage above a velocity threshold, failed authentication bursts. Delivered via webhook, email, or PagerDuty integration.

Physical Security

Co-Location Facility Standards

EurekaLabs hardware lives in SOC 2 Type II certified Equinix data centers with the physical controls institutional clients require.

Biometric Cage Access

Access to EurekaLabs cage space requires multi-factor physical authentication including biometric verification and escort by EurekaLabs personnel for any client representative visit.

24/7 CCTV Monitoring

Continuous CCTV coverage of the cage floor with a 90-day retention period. Footage is available to clients involved in a security review under NDA.

SOC 2 Type II

Equinix NY4 and NY5 hold current SOC 2 Type II reports covering physical and environmental controls. EurekaLabs designs its application and operations layer to SOC 2 criteria and is pursuing its own Type II certification. Contact us for our current security documentation under NDA.

Redundant Power and Connectivity

Each server receives power from two independent PDUs on separate utility feeds with UPS backup and generator redundancy. Cross-connects from multiple fiber carriers with automated failover.

Due Diligence

Security Documentation Available on Request

SOC 2 reports, penetration test summaries, encryption key management policy, and our incident response playbook are available to qualified firms under NDA during the evaluation process.