Skip to main content
Trust Center

Everything your risk team needs to verify.

Institutional buyers seat vendors on rigor, not claims. This is the single place to assess how Market Fortress handles your data, your obligations, and your liability, with each commitment linked to the page that proves it.

Security

Four layers around the data

Row-level security on every table, AES-256-GCM for material non-public information at rest, isolated AI routing, and an append-only mutation log. Built around MNPI handling requirements rather than retrofitted to them.

Review the architecture
Regulatory coverage

Every event, every consequence

A single material event raises every downstream obligation it triggers across the platform: deadlines, drafting tasks, and the notifications that route them to the right role. Nothing is left for an issuer to remember.

See material events
Oversight

The platform is a tool. Counsel signs.

Market Fortress drafts, surfaces, and routes. It does not file. The signing attorney remains the responsible party on every submission, with a complete record of what was reviewed, when, and by whom.

How counsel oversight works
Data ownership

No lock-in at the data layer

The complete dataset is extractable at any time in JSON and CSV. There are no soft deletes. Every record carries its own lineage, and the issuer owns it for the full retention period.

Data processing terms
Availability

Uptime built for filing deadlines

A 99.9% availability target during US market hours. Filing-deadline traffic is prioritized over non-critical workloads. Status and historical incidents publish at status.marketfortress.app.

View system status
Privacy

Privacy and compliance by construction

GDPR Article 17 erasure, CCPA and CPRA consumer rights, per-issuer key isolation, and a documented subprocessor list. Privacy controls are enforced server-side, not promised in a policy.

Read the privacy policy
Connected by Construction

One event raises every obligation it triggers.

The modules are not silos. When something happens inside an issuer, the platform resolves the full set of downstream consequences across every domain it touches, anchors each deadline to the statutory clock, and routes the work to the responsible role. The issuer is not asked to know which obligations a given event creates.

Periodic reporting

10-K, 10-Q, and 8-K clocks anchored to the underlying event and the issuer filer category, not to the date a user happened to enter the data.

Material events

The full set of Form 8-K disclosure items, each with its own four-business-day clock and the drafting task it requires.

Insider activity

Section 16 ownership reports, Rule 10b5-1 trading plans with cooling-off enforcement, and the single-plan rule check.

Beneficial ownership

Schedule 13D and 13G threshold monitoring with the filing schedule each crossing triggers, surfaced into the global calendar.

Restatement and recovery

Dodd-Frank Rule 10D-1 clawback analysis, excess-compensation recompute, and the ICFR and proxy disclosure obligations that follow.

Cybersecurity disclosure

Item 1.05 materiality determinations that start the four-business-day clock, with the DOJ delay pathway tracked alongside.

Capital and offerings

Registered and exempt offerings, Reg D state Blue Sky obligations, and the disclosure tasks each financing path raises.

Governance and exchange

Board, committee, and listing-standard events routed to the right persona with the proxy and exchange notices they require.

Deadlines anchor to the underlying event date and the issuer filer category, computed on business days where the rule requires it. Coverage breadth is data, reviewable and extendable, not a fixed set of hard-coded paths.

Verifiable Controls

Control posture, mapped to the frameworks your auditors use.

This view is computed live from the platform control engine at page load, not maintained by hand. Each control maps to SOC 2, ISO 27001, NIST CSF 2.0, and the SEC cybersecurity disclosure rules. The signed attestation, with the underlying evidence for every control, is available to your risk team on request.

SOC 2
67%

5 of 24 machine-checked, 11 documented, 8 in progress

ISO 27001
50%

2 of 4 machine-checked, 2 in progress

NIST CSF 2.0
40%

2 of 5 machine-checked, 3 in progress

SEC Cybersecurity
100%

0 of 3 machine-checked, 3 documented

Security

7 of 14 verified

Availability

2 of 2 verified

Processing Integrity

2 of 2 verified

Confidentiality

2 of 2 verified

Privacy

3 of 4 verified

SOC 2

CC6.1
Logical and Physical Access Controls
Verified
CC6.6
Encryption of Data in Transit
In progress
CC6.7
Encryption of Data at Rest
Verified
CC6.8
Prevention of Unauthorized Software
In progress
CC7.2
Monitoring of System Components
In progress
CC7.3
Data Loss Prevention
In progress
CC1.1
Control Environment and Integrity
In progress
CC2.1
Communication of Security Commitments
Documented
CC3.1
Risk Assessment
Documented
CC4.1
Monitoring of Controls
In progress
CC5.1
Control Activities
Documented
CC7.4
Incident Response
Documented
CC8.1
Change Management
Documented
CC9.1
Risk Mitigation: Vendors
In progress
A1.1
Capacity and Resilience
Verified
A1.2
Backup and Recovery
Documented
PI1.1
Completeness and Accuracy of Processing
Documented
PI1.2
Integrity of the Record
Documented
C1.1
Confidential Information Protection
Verified
C1.2
Confidential Information Disposal
Verified
P1.1
Privacy Notice
Documented
P4.1
Retention and Disposal
Documented
P6.1
Access, Correction, and Erasure
Documented
P8.1
Privacy Monitoring and Enforcement
In progress

ISO 27001

A.8.24
Use of Cryptography
Verified
A.8.5
Secure Authentication
In progress
A.8.10
Information Deletion
Verified
A.8.12
Data Leakage Prevention
In progress

NIST CSF 2.0

PR.DS-1
Data at Rest Protection
Verified
PR.DS-2
Data in Transit Protection
In progress
PR.AC-7
Strong Authentication
In progress
DE.CM-1
Continuous Monitoring
In progress
ID.SC-2
Quantum-Resistant Cryptography
Verified

SEC Cybersecurity

Item 1.05
Cybersecurity Risk Management
Documented
Item 106(b)
Board Oversight of Cybersecurity
Documented
Item 106(c)
Cybersecurity Strategy
Documented

Controls marked verified are checked by an automated probe each time this page is generated, and the status shown is that probe's result. Controls marked documented are satisfied by a published policy, runbook or process rather than by a live check. Controls shown in progress are not currently demonstrable by probe, and are stated that way deliberately rather than presented as verified. Market Fortress is not SOC 2 certified; this is a self-assessment. Evidence and the signed attestation are released to risk teams under standard diligence.

Have a diligence question?

Our team answers every standard vendor risk assessment and can supply contractual language on liability and service levels on request.

Trust Center | Market Fortress