Security/Operational Assurance
Evidence-Based Security Model

Security & Operational Assurance

Access Controls, Secure Engineering & Demonstrable Protection

Access controls, secure development practices and incident response for Orrnn's trading infrastructure. Security architecture, plainly explained.

Publishing only demonstrable controls enforced in production today, each documented with last review dates

Assurance BaselineActive Posture
Access ModelLeast-Privilege RBAC
Encryption In TransitTLS 1.3 Strict
Encryption At RestAES-256 + Client KMS
Incident TriageTarget < 15m Response
SECURITY POLICYNO UNVERIFIED BADGES
shield_lock
Security Evidence Standard

Evidence-Based Assurance — No Unverified Marketing Badges

Orrnn does not publish unbacked certification logos or marketing badges. Controls published on this page are demonstrable and actively enforced today. Formal SOC 2 Type II packages, third-party penetration test summaries, and threat models are made available directly to institutional procurement teams under mutual NDA.

Request NDA Packagearrow_forward
Active Safeguards

Demonstrable Security Controls

The following technical controls are actively demonstrable in Orrnn's codebase, cloud infrastructure, and deployment templates. Each control includes its formal identifier and last review date:

SEC-CTL-01Data Protection
Demonstrable Today

TLS 1.3 Transport Encryption

Strict TLS 1.3 cipher suite enforcement across all client terminals, WebSockets, and FIX API ingress gateways. Legacy protocols (SSLv3, TLS 1.0, 1.1) are rejected at the edge.

LAST REVIEWED:2026-09-01
✓ Evidence: Enforced via edge reverse proxy configurations; tested with SSL Labs A+ profile.
SEC-CTL-02Access & Identity
Demonstrable Today

Role-Based Access Control (RBAC)

Explicit principle of least-privilege governing all administrative actions. Strict permission boundaries separate Traders, Risk Managers, Platform Operators, and Compliance Auditors.

LAST REVIEWED:2026-08-20
✓ Evidence: Policy enforcement verified in broker administrative session tokens and API authorization gates.
SEC-CTL-03Access & Identity
Demonstrable Today

Hardware-Backed Multi-Factor Auth (MFA)

Mandatory FIDO2 WebAuthn hardware keys or TOTP authenticators for all administrative accounts, deployment pipelines, and sensitive operational consoles.

LAST REVIEWED:2026-08-15
✓ Evidence: MFA challenge required on all non-public administrative sessions; zero password-only access.
SEC-CTL-04Software Lifecycle
Demonstrable Today

Automated SAST & Dependency Vulnerability Scanning

Continuous Static Application Security Testing (SAST) and Software Composition Analysis (SCA) embedded in the CI/CD pipeline. Pull requests with High or Critical CVEs are automatically blocked.

LAST REVIEWED:2026-09-10
✓ Evidence: Automated GitHub Actions security gates blocking merges on unmitigated vulnerabilities.
SEC-CTL-05Infrastructure Defense
Demonstrable Today

Immutable Audit Trail & Drop-Copy Logging

Append-only, cryptographically hashed transactional audit log recording every order lifecycle event, administrative privilege escalation, and risk engine override.

LAST REVIEWED:2026-08-28
✓ Evidence: Out-of-band FIX Drop-Copy streaming and write-once cloud object storage.
SEC-CTL-06Infrastructure Defense
Demonstrable Today

cgroups v2 Process & Memory Isolation

Linux container process sandboxing and cgroups v2 resource accounting isolating automated trading strategies, preventing memory leakage or CPU hogging from impacting core matching.

LAST REVIEWED:2026-09-05
✓ Evidence: Kernel namespace and cgroups limits verified on all strategy runner instances.
SEC-CTL-07Data Protection
Demonstrable Today

AES-256 Storage Encryption with Client KMS

Full volume and database encryption at rest utilizing AES-256. In dedicated cloud or on-premise deployments, brokers maintain complete custody of their encryption keys.

LAST REVIEWED:2026-08-18
✓ Evidence: FIPS 140-2 validated cryptographic modules and client-managed KMS integration.
SEC-CTL-08Infrastructure Defense
Demonstrable Today

Ingress Token-Bucket Rate Limiting

Adaptive network rate-limiting and connection throttling protecting FIX and WebSocket gateways from connection exhaustion, packet floods, and volumetric DDoS attacks.

LAST REVIEWED:2026-09-12
✓ Evidence: Hardware and software rate-limiters active on all colocation and cloud edge nodes.
badge
GOVERNANCE_LAYER_01

Access Model & Least-Privilege

Administrative access is governed by strict zero-trust principles. No individual or automated process has unilateral access across separate layers of the trading stack:

  • check_circle
    Granular Role SeparationTraders can only execute and manage orders; Risk Officers hold margin configuration permissions; Auditors hold read-only drop-copy access.
  • check_circle
    Ephemeral Session TokensAdministrative tokens are short-lived (maximum 60-minute duration) and cryptographically bound to specific originating IP ranges.
  • check_circle
    Scoped Machine AccountsAutomated algorithms and background daemons connect via scoped mTLS API keys without interactive console privileges.
terminal
GOVERNANCE_LAYER_02

Secure Engineering Lifecycle

Security is integrated into every phase of software development, from architecture threat modeling to continuous artifact signing:

  • check_circle
    Multi-Peer Review & Branch ProtectionDirect commits to release branches are disabled. All code changes require mandatory review by at least two senior systems engineers.
  • check_circle
    Cryptographically Signed BinariesRelease binaries and container images are cryptographically signed with internal hardware security keys before deployment.
  • check_circle
    Continuous Fuzzing & Stress TestsEngine parsing protocols undergo continuous synthetic fuzz testing to detect buffer overflows, malformed packet crashes, and race conditions.
Operational Continuity

Incident Response Process

When an anomaly, infrastructure degradation, or security event occurs, our operational response follows four defined, deterministic stages:

01Target < 5m

Detection & Triaging

Automated telemetry probes, heartbeat monitors, and anomaly thresholds trigger high-priority alerts to on-call infrastructure engineers 24/7.

STEP // PROBE_ALERT_FIRE
02Target < 15m

Isolation & Containment

Affected sessions or nodes are automatically isolated via traffic shedding, gateway disconnects, or routing traffic to pre-warmed standby instances.

STEP // TRAFFIC_ISOLATION
03Target < 60m

Remediation & Validation

Senior engineers apply vetted patches or automated state reconciliation. Trade ledgers are cryptographically verified before returning nodes to live routing.

STEP // HOTFIX_RECONCILIATION
04Within 24h

Post-Mortem & Disclosure

A comprehensive root-cause analysis (RCA) report is compiled and delivered directly to impacted enterprise partners, including preventative action items.

STEP // POST_MORTEM_RCA
Responsible Vulnerability Disclosure

Security Researcher Reporting Channel

If you believe you have discovered a security vulnerability in Orrnn software, please submit your findings to our security team. We ask for coordinated disclosure and will acknowledge receipt within 24 business hours.

mailsecurity@orrnn.com
Institutional Due Diligence

Request Security Documentation

Connect directly with our security and engineering leadership to receive our detailed operational assurance package under mutual NDA.

Optional analytics

Orrnn loads Google Analytics only if you accept. It is not required for the site, guides, calculators, downloads, or contact forms. Read the privacy policy.