Security Questions to Ask a Prop Firm Software Vendor
Prop-tech platforms can hold customer, account, KYC-status, payment-reference and operational data. Security diligence should focus on current controls and evidence, not a badge list copied from a sales page.
Access control
- Does the platform support granular RBAC?
- Can sensitive payout/risk actions require separate roles?
- Are administrator actions audited?
- How is vendor support access controlled and logged?
Authentication
- MFA options for administrators.
- SSO/enterprise identity where required.
- Session controls.
- Credential/key rotation.
Data
- Where is data stored?
- Encryption in transit/at rest.
- Backup and restore process.
- Retention/deletion.
- Tenant isolation.
- Export controls.
Incident management
Ask how incidents are detected, classified and communicated, who receives notifications and what post-incident evidence is available. Security response and availability response may use different processes.
Certifications and audits
Request current evidence and scope. A roadmap is not a certification. Tradaxi's public material, for example, has referenced a SOC 2 roadmap; buyers should not convert that into a current SOC 2 claim.
Third parties
Identify hosting, KYC, email, analytics and other subprocessors/dependencies relevant to the service. Determine which sensitive data each receives.
API security
Review authentication, permissions, webhook signatures, replay protection, rate limiting and auditability for programmatic actions.
Business continuity
Security includes recovery. Ask about backups, recovery objectives, credential compromise procedures and how critical account/risk state is reconciled after an incident.
Evidence to request
- Security overview/architecture.
- Current audit/certification evidence where claimed.
- Pen-test summary where appropriate/available.
- Incident notification terms.
- DPA/subprocessor information where applicable.
- Access-control demonstration.
This is a procurement framework, not a certification of any provider. Pair it with our due diligence guide, SLA guide and data guide.
FAQ
Should a prop firm require SOC 2?
That depends on the buyer's risk, customers and requirements. If a certification is mandatory, request current scoped evidence rather than relying on roadmap language.
Is cloud hosting automatically secure?
No. Cloud providers supply infrastructure controls, while application configuration, access, data handling and operational security remain important.