Security & Operational Assurance
Access Controls, Secure Engineering & Demonstrable Protection
Access controls, secure development practices and incident response for Orrnn's trading infrastructure. Security architecture, plainly explained.
Publishing only demonstrable controls enforced in production today, each documented with last review dates
Evidence-Based Assurance — No Unverified Marketing Badges
Orrnn does not publish unbacked certification logos or marketing badges. Controls published on this page are demonstrable and actively enforced today. Formal SOC 2 Type II packages, third-party penetration test summaries, and threat models are made available directly to institutional procurement teams under mutual NDA.
Demonstrable Security Controls
The following technical controls are actively demonstrable in Orrnn's codebase, cloud infrastructure, and deployment templates. Each control includes its formal identifier and last review date:
TLS 1.3 Transport Encryption
Strict TLS 1.3 cipher suite enforcement across all client terminals, WebSockets, and FIX API ingress gateways. Legacy protocols (SSLv3, TLS 1.0, 1.1) are rejected at the edge.
Role-Based Access Control (RBAC)
Explicit principle of least-privilege governing all administrative actions. Strict permission boundaries separate Traders, Risk Managers, Platform Operators, and Compliance Auditors.
Hardware-Backed Multi-Factor Auth (MFA)
Mandatory FIDO2 WebAuthn hardware keys or TOTP authenticators for all administrative accounts, deployment pipelines, and sensitive operational consoles.
Automated SAST & Dependency Vulnerability Scanning
Continuous Static Application Security Testing (SAST) and Software Composition Analysis (SCA) embedded in the CI/CD pipeline. Pull requests with High or Critical CVEs are automatically blocked.
Immutable Audit Trail & Drop-Copy Logging
Append-only, cryptographically hashed transactional audit log recording every order lifecycle event, administrative privilege escalation, and risk engine override.
cgroups v2 Process & Memory Isolation
Linux container process sandboxing and cgroups v2 resource accounting isolating automated trading strategies, preventing memory leakage or CPU hogging from impacting core matching.
AES-256 Storage Encryption with Client KMS
Full volume and database encryption at rest utilizing AES-256. In dedicated cloud or on-premise deployments, brokers maintain complete custody of their encryption keys.
Ingress Token-Bucket Rate Limiting
Adaptive network rate-limiting and connection throttling protecting FIX and WebSocket gateways from connection exhaustion, packet floods, and volumetric DDoS attacks.
Access Model & Least-Privilege
Administrative access is governed by strict zero-trust principles. No individual or automated process has unilateral access across separate layers of the trading stack:
- check_circleGranular Role SeparationTraders can only execute and manage orders; Risk Officers hold margin configuration permissions; Auditors hold read-only drop-copy access.
- check_circleEphemeral Session TokensAdministrative tokens are short-lived (maximum 60-minute duration) and cryptographically bound to specific originating IP ranges.
- check_circleScoped Machine AccountsAutomated algorithms and background daemons connect via scoped mTLS API keys without interactive console privileges.
Secure Engineering Lifecycle
Security is integrated into every phase of software development, from architecture threat modeling to continuous artifact signing:
- check_circleMulti-Peer Review & Branch ProtectionDirect commits to release branches are disabled. All code changes require mandatory review by at least two senior systems engineers.
- check_circleCryptographically Signed BinariesRelease binaries and container images are cryptographically signed with internal hardware security keys before deployment.
- check_circleContinuous Fuzzing & Stress TestsEngine parsing protocols undergo continuous synthetic fuzz testing to detect buffer overflows, malformed packet crashes, and race conditions.
Incident Response Process
When an anomaly, infrastructure degradation, or security event occurs, our operational response follows four defined, deterministic stages:
Detection & Triaging
Automated telemetry probes, heartbeat monitors, and anomaly thresholds trigger high-priority alerts to on-call infrastructure engineers 24/7.
Isolation & Containment
Affected sessions or nodes are automatically isolated via traffic shedding, gateway disconnects, or routing traffic to pre-warmed standby instances.
Remediation & Validation
Senior engineers apply vetted patches or automated state reconciliation. Trade ledgers are cryptographically verified before returning nodes to live routing.
Post-Mortem & Disclosure
A comprehensive root-cause analysis (RCA) report is compiled and delivered directly to impacted enterprise partners, including preventative action items.
Security Researcher Reporting Channel
If you believe you have discovered a security vulnerability in Orrnn software, please submit your findings to our security team. We ask for coordinated disclosure and will acknowledge receipt within 24 business hours.
Request Security
Documentation
Connect directly with our security and engineering leadership to receive our detailed operational assurance package under mutual NDA.