Skip to content
MARKET CONTEXT PLATFORMNOT FINANCIAL ADVICE

What buyers can verify about security.

Buyer-readable security summary: infrastructure location, access control, compliance posture, and responsible disclosure in one place.

Use this page to verify what is in place, what is partial, and what has not been externally audited yet before treating any security claim as settled.

Last updated: June 2026

Published by MarketDepth Analytics OÜ (registry code 17549629, Estonia), the legal entity behind DepthSignal.

What This Covers

Infrastructure location, access controls, encryption posture, subprocessors, and disclosure workflow.

What Is Proven Here

Current control posture, what is complete, what is partial, and which assurance items have not been externally audited yet.

What This Is Not

This page is a public summary, not a claim that every framework is certified or every artifact is disclosed publicly.

Our security posture

DepthSignal serves quantitative analysts, trading desks, and data science teams that need reliable orderbook data. We maintain ISO 27001-aligned internal controls and ISMS artifacts, with policies, a risk register, and regular management reviews. No external ISO 27001 audit or certificate has been completed. This page gives buyers key security details in one place. If you need more, contact [email protected].

Data residency

All production infrastructure runs on Hetzner datacentres in Germany and Finland (European Union). Customer data stays in the EEA unless it is sent to subprocessors outside the EEA under GDPR Chapter V safeguards where applicable. The core current public workflow set is listed below. Additional optional or configuration-dependent providers are disclosed in the DPA and current subprocessor records.

  • Payment-provider path is currently inactive: There is no active payment provider currently proved. Payment processing or subscription billing resumes only if a future provider is attached to the universal provider-agnostic payment runtime and that checkout path is re-published in current legal materials. While there is no active payment provider currently proved, the only published fallback is a bounded direct/manual path for manual invoicing plus SEPA bank transfer. DepthSignal's own finance/tax system remains the central authority and system of record for payment references, invoice records, refund records, settlement tracking, and VAT/GST monitoring, and any future PSP or bank rail must attach to that internal system as an adapter. This does not by itself prove operational revalidation, self-serve checkout, a current payable path, live card processing, PSP webhooks, generic automated invoice delivery, or settlement execution.
  • Resend: transactional email (GDPR Chapter V safeguards; see current DPA Section 9)
  • Linear, Inc.: automatic bug report ticket creation and follow-up (GDPR Chapter V safeguards; see current DPA Section 9)
  • OpenAI OpCo LLC: AI chat feature, when enabled by the customer (GDPR Chapter V safeguards; see current DPA Section 9)
  • Cloudflare: CDN and DDoS mitigation (GDPR Chapter V safeguards; EU nodes for EU traffic)

PostHog analytics is self-hosted on our Hetzner EU infrastructure. PostHog Inc. does not receive customer analytics events, so this does not create a third-party subprocessor transfer.

Hetzner states its datacentre operations are covered by ISO 27001 audited controls. Physical security includes 24/7 staff, CCTV, controlled access, and redundant power and cooling.

The customer-facing API runs in a dedicated network zone, separate from internal data and processing services. Network segmentation and least-privilege service access help reduce blast radius if a component is compromised.

Security and compliance frameworks

We show what is done and what is still in progress. The table below reflects our current state.

GDPR

Controls in place

We act as data controller. DPA is published. Current self-service rights endpoints cover account/API/usage/security-event/AI-conversation export plus rectification, erasure, and analytics opt-out. Newsletter subscriber export coverage remains an open gap under AF-006 / NC-2026-006. Article 30 records are documented. Breach notification process is in place (72h AKI notification).

Actively maintained

ISO/IEC 27001:2022

Partial

We maintain ISO 27001-aligned internal controls and ISMS artifacts, including policies, quarterly management reviews, a risk register, and a Statement of Applicability. No external ISO 27001 audit or certificate has been completed.

External audit not completed.

SOC 2 Type II

Not started

SOC 2 observation window has not started. Core controls mapped to Trust Service Criteria are in place (access control, monitoring, availability, incident response). Formal SOC 2 audit will start when budget allows.

Observation window planned when ARR justifies cost.

ISO 27001 status means internal control alignment against our Statement of Applicability (ISMS-02). It is not an external audit result.

Controls highlights

Access control

Customer passwordsWe hash passwords with PBKDF2-HMAC-SHA256, 600,000 iterations (NIST SP 800-132). We also check new and reset passwords against known breach data using a k-anonymity API.
Two-factor authenticationTOTP (optional for customers; mandatory for all internal company access).
Brute-force protectionAutomated controls detect brute-force attempts and apply temporary protection when risk is high.
API keysAPI keys are hashed at rest. The plain key is shown once when created and cannot be recovered later.
Internal accessInternal controls are limited to authorized staff with least-privilege access. Sensitive actions require MFA and extra verification.
Internal operations logSecurity-related internal actions are written to append-only audit records with integrity checks. Retention follows legal and compliance rules.

Encryption and transport

Data in transitExternal traffic uses TLS (1.2+). HSTS is enabled on supported production endpoints.
Certificate managementAutomated provisioning and renewal via Let's Encrypt.
DDoS / TLS terminationCloudflare in front of public application endpoints.
Customer passwordsPasswords are hashed with PBKDF2-HMAC-SHA256, 600,000 iterations (NIST SP 800-132).
API keysOne-way cryptographic hash. Plaintext is not retained after issuance.

Application security

Input validationCore APIs use schema validation with typed models.
SQL injectionProduction services use parameterized queries and ORM safeguards.
Error handlingGeneric messages to clients. Stack traces logged server-side only.
Automated attack detectionSecurity middleware and monitoring detect malicious request patterns and apply automated protection.
Mandatory code reviewChanges to production systems require peer review before deployment.
Automated testsWe run automated tests, including end-to-end tests for critical paths.

Monitoring and incident response

Service watchdogWe continuously monitor service health with automated recovery and on-call escalation.
Breach detectionWe run anomaly detection and alerting across authentication, data access, and platform behavior.
Security event logSecurity events are stored in append-only audit records with integrity controls. Retention follows legal and compliance rules.
Incident notificationPersonal data breach notification to Estonian DPA (AKI) within 72 hours of becoming aware, per GDPR Article 33.

Backup and business continuity

Backup cadenceAutomated backups run on a schedule across core data stores and critical app state.
RetentionBackup retention follows a documented schedule based on recovery and legal needs.
RedundancyHetzner-managed infrastructure with automated snapshots independent of the application layer. Encrypted offsite backup expansion in progress.
RTO / RPORecovery targets are defined, reviewed, and tested in our business continuity process.

GDPR and data rights

DepthSignal is operated by MarketDepth Analytics OÜ as the customer-facing controller. Ravenna OÜ provides the declared operational data-processing function under contract. The supervisory authority is the Estonian Data Protection Inspectorate (AKI).

Customers can exercise their rights at any time via the platform:

RightHow to exercise
Access (Art. 15)GET /v1/customer/export - current account/API/usage/security-event/AI-conversation JSON export; newsletter subscriber export remains open under AF-006 / NC-2026-006
Rectification (Art. 16)PATCH /v1/customer/me
Erasure (Art. 17)DELETE /v1/customer/me - removes live account/API/usage data; billing records and Article 16(m) consent evidence can remain on their own legal-retention basis
Portability (Art. 20)GET /v1/customer/export - machine-readable current account/API/usage/security-event/AI-conversation export; newsletter subscriber export remains open under AF-006 / NC-2026-006
Opt-out of analytics (Art. 21)POST /v1/customer/me/analytics/opt-out

Current self-service GDPR-rights endpoints are available for export, rectification, erasure, and analytics opt-out through GET /v1/customer/export, PATCH /v1/customer/me, DELETE /v1/customer/me, and POST /v1/customer/me/analytics/opt-out.

Subprocessors

The subprocessors below cover the current public workflow set. Transfer rules apply where data leaves the EEA. Optional or configuration-dependent providers remain documented in the DPA and current subprocessor records.

SubprocessorPurposeTransfer mechanism
Hetzner Online GmbHCloud infrastructure, compute, storageEU/EEA (Germany, Finland). No international transfer.
Payment-provider path (currently inactive; no active payment provider currently proved)Payment processing and subscription billing only if a future provider is attached to the universal provider-agnostic payment runtime and a paid checkout path is then activated again. While there is no active payment provider currently proved, the only published fallback is a bounded direct/manual path for manual invoicing plus SEPA bank transfer. DepthSignal's own finance/tax system remains the central authority and system of record for payment references, invoice records, refund records, settlement tracking, and VAT/GST monitoring, and any future PSP or bank rail must attach to that internal system as an adapter. This does not by itself prove operational revalidation, self-serve checkout, a current payable path, live card processing, PSP webhooks, generic automated invoice delivery, or settlement execution.There is no active payment provider currently proved. The only published fallback while there is no active payment provider currently proved is a bounded direct/manual path for manual invoicing plus SEPA bank transfer. If a future provider is attached to the universal provider-agnostic payment runtime and a payment-provider path is then activated again, its role, region, and transfer basis must be published in the then-current subprocessor and DPA materials before activation.
Resend Inc.Transactional email deliveryGDPR Chapter V safeguards (see current DPA Section 9)
Linear, Inc.Automatic bug report ticket creation and issue follow-up for voluntarily submitted reportsGDPR Chapter V safeguards (see current DPA Section 9)
OpenAI OpCo LLCAI chat feature (when enabled by customer)GDPR Chapter V safeguards (see current DPA Section 9)
Cloudflare Inc.CDN, DDoS mitigation, TLS terminationGDPR Chapter V safeguards (see current DPA Section 9); EU customers served from EU edge nodes

Self-hosted analytics note: PostHog software runs on our own EU infrastructure. No PostHog Inc. processor transfer occurs.

We give at least 30 days notice for material subprocessor changes. Requests for additional subprocessor documentation can be sent to [email protected].

Compliance resources

You may contact [email protected]. to request additional security and compliance materials.

For security reasons, the public page is a summary. Detailed evidence is shared under NDA during qualified due diligence.

Assurance artifacts

Teams running formal security review can request a current assurance pack with control summaries, evidence mapping, and process documents for vendor security reviews.

  • ISMS control mapping and Statement of Applicability references
  • Business continuity and incident response process summaries
  • Subprocessor and transfer mechanism documentation.
  • Data protection controls, retention rules, and deletion workflow evidence

Responsible disclosure

If you discover a security vulnerability in the DepthSignal platform, report it to [email protected].

Response commitments

  • We acknowledge good-faith security reports through the active disclosure workflow after receipt and validation.
  • Severity triage and response routing follow the active disclosure workflow after the report is confirmed as in scope.
  • Coordinated disclosure timing follows the active disclosure workflow after a valid issue is confirmed.
  • We intend to treat good-faith security research that stays within this policy as responsible disclosure rather than abusive use, while reserving the right to take proportionate action to protect users, systems, and legal obligations.

PGP encryption

If you would prefer to submit an encrypted report, email [email protected] to request the current encrypted-report instructions.

Scope

In scope: depthsignal.io, api.depthsignal.io, sentinel.depthsignal.io, and other targets confirmed by our security team. Out of scope: infrastructure not run by MarketDepth Analytics OÜ and third-party subprocessors (Cloudflare, payment providers, etc.).

Full acceptable-use policy: /legal/acceptable-use §4.

Contact

Security review and procurement

For security questionnaires, vendor assessments, or procurement due diligence, contact [email protected]. DPA requests and legal correspondence should be sent to [email protected].

Security issues

[email protected] (vulnerability reports and security questions only).

Legal and data protection

[email protected] (DPA requests, GDPR rights, legal correspondence).

MarketDepth Analytics OÜ

Registry code: 17549629 · Estonia

This document is reviewed at least annually. For the most current version, contact [email protected].

Security, Infrastructure, and Data Protection | DepthSignal