Skip to main content
Trust Center

Everything your risk team needs to verify.

Institutional buyers seat vendors on rigor, not claims. This is the single place to assess how Market Fortress handles your data, your obligations, and your liability, with each commitment linked to the page that proves it.

Security

Four layers around the data

Row-level security on every table, AES-256-GCM for material non-public information at rest, isolated AI routing, and an append-only mutation log. Built around MNPI handling requirements rather than retrofitted to them.

Review the architecture
Regulatory coverage

Every event, every consequence

A single material event raises every downstream obligation it triggers across the platform: deadlines, drafting tasks, and the notifications that route them to the right role. Nothing is left for an issuer to remember.

See material events
Oversight

The platform is a tool. Counsel signs.

Market Fortress drafts, surfaces, and routes. It does not file. The signing attorney remains the responsible party on every submission, with a complete record of what was reviewed, when, and by whom.

How counsel oversight works
Data ownership

No lock-in at the data layer

The complete dataset is extractable at any time in JSON and CSV. There are no soft deletes. Every record carries its own lineage, and the issuer owns it for the full retention period.

Data processing terms
Availability

Uptime built for filing deadlines

A 99.9% availability target during US market hours. Filing-deadline traffic is prioritized over non-critical workloads. Status and historical incidents publish at status.marketfortress.app.

View system status
Privacy

Privacy and compliance by construction

GDPR Article 17 erasure, CCPA and CPRA consumer rights, per-issuer key isolation, and a documented subprocessor list. Privacy controls are enforced server-side, not promised in a policy.

Read the privacy policy
Connected by Construction

One event raises every obligation it triggers.

The modules are not silos. When something happens inside an issuer, the platform resolves the full set of downstream consequences across every domain it touches, anchors each deadline to the statutory clock, and routes the work to the responsible role. The issuer is not asked to know which obligations a given event creates.

Periodic reporting

10-K, 10-Q, and 8-K clocks anchored to the underlying event and the issuer filer category, not to the date a user happened to enter the data.

Material events

The full set of Form 8-K disclosure items, each with its own four-business-day clock and the drafting task it requires.

Insider activity

Section 16 ownership reports, Rule 10b5-1 trading plans with cooling-off enforcement, and the single-plan rule check.

Beneficial ownership

Schedule 13D and 13G threshold monitoring with the filing schedule each crossing triggers, surfaced into the global calendar.

Restatement and recovery

Dodd-Frank Rule 10D-1 clawback analysis, excess-compensation recompute, and the ICFR and proxy disclosure obligations that follow.

Cybersecurity disclosure

Item 1.05 materiality determinations that start the four-business-day clock, with the DOJ delay pathway tracked alongside.

Capital and offerings

Registered and exempt offerings, Reg D state Blue Sky obligations, and the disclosure tasks each financing path raises.

Governance and exchange

Board, committee, and listing-standard events routed to the right persona with the proxy and exchange notices they require.

Deadlines anchor to the underlying event date and the issuer filer category, computed on business days where the rule requires it. Coverage breadth is data, reviewable and extendable, not a fixed set of hard-coded paths.

Verifiable Controls

Control posture, mapped to the frameworks your auditors use.

This view is computed live from the platform control engine at page load, not maintained by hand. Each control maps to SOC 2, ISO 27001, NIST CSF 2.0, and the SEC cybersecurity disclosure rules. The signed attestation, with the underlying evidence for every control, is available to your risk team on request.

SOC 2
92%

22 of 24 controls verified, 2 in progress

ISO 27001
100%

4 of 4 controls verified

NIST CSF 2.0
100%

5 of 5 controls verified

SEC Cybersecurity
100%

3 of 3 controls verified

Security

12 of 14 verified

Availability

2 of 2 verified

Processing Integrity

2 of 2 verified

Confidentiality

2 of 2 verified

Privacy

4 of 4 verified

SOC 2

CC6.1
Logical and Physical Access Controls
Verified
CC6.6
Encryption of Data in Transit
Verified
CC6.7
Encryption of Data at Rest
Verified
CC6.8
Prevention of Unauthorized Software
Verified
CC7.2
Monitoring of System Components
Verified
CC7.3
Data Loss Prevention
Verified
CC1.1
Control Environment and Integrity
In progress
CC2.1
Communication of Security Commitments
Verified
CC3.1
Risk Assessment
Verified
CC4.1
Monitoring of Controls
Verified
CC5.1
Control Activities
Verified
CC7.4
Incident Response
Verified
CC8.1
Change Management
Verified
CC9.1
Risk Mitigation: Vendors
In progress
A1.1
Capacity and Resilience
Verified
A1.2
Backup and Recovery
Verified
PI1.1
Completeness and Accuracy of Processing
Verified
PI1.2
Integrity of the Record
Verified
C1.1
Confidential Information Protection
Verified
C1.2
Confidential Information Disposal
Verified
P1.1
Privacy Notice
Verified
P4.1
Retention and Disposal
Verified
P6.1
Access, Correction, and Erasure
Verified
P8.1
Privacy Monitoring and Enforcement
Verified

ISO 27001

A.8.24
Use of Cryptography
Verified
A.8.5
Secure Authentication
Verified
A.8.10
Information Deletion
Verified
A.8.12
Data Leakage Prevention
Verified

NIST CSF 2.0

PR.DS-1
Data at Rest Protection
Verified
PR.DS-2
Data in Transit Protection
Verified
PR.AC-7
Strong Authentication
Verified
DE.CM-1
Continuous Monitoring
Verified
ID.SC-2
Quantum-Resistant Cryptography
Verified

SEC Cybersecurity

Item 1.05
Cybersecurity Risk Management
Verified
Item 106(b)
Board Oversight of Cybersecurity
Verified
Item 106(c)
Cybersecurity Strategy
Verified

Verified controls are continuously checked by the platform. Controls shown in progress are organizational measures being formalized on the documented review cadence. Evidence and the cryptographically signed attestation are released to risk teams under standard diligence.

Have a diligence question?

Our team answers every standard vendor risk assessment and can supply contractual language on liability and service levels on request.

Trust Center | Market Fortress