What buyers can verify about security.
Buyer-readable security summary: infrastructure location, access control, compliance posture, and responsible disclosure in one place.
Use this page to verify what is in place, what is partial, and what has not been externally audited yet before treating any security claim as settled.
Last updated: June 2026
Published by MarketDepth Analytics OÜ (registry code 17549629, Estonia), the legal entity behind DepthSignal.
What This Covers
Infrastructure location, access controls, encryption posture, subprocessors, and disclosure workflow.
What Is Proven Here
Current control posture, what is complete, what is partial, and which assurance items have not been externally audited yet.
What This Is Not
This page is a public summary, not a claim that every framework is certified or every artifact is disclosed publicly.
Our security posture
DepthSignal serves quantitative analysts, trading desks, and data science teams that need reliable orderbook data. We maintain ISO 27001-aligned internal controls and ISMS artifacts, with policies, a risk register, and regular management reviews. No external ISO 27001 audit or certificate has been completed. This page gives buyers key security details in one place. If you need more, contact [email protected].
Data residency
All production infrastructure runs on Hetzner datacentres in Germany and Finland (European Union). Customer data stays in the EEA unless it is sent to subprocessors outside the EEA under GDPR Chapter V safeguards where applicable. The core current public workflow set is listed below. Additional optional or configuration-dependent providers are disclosed in the DPA and current subprocessor records.
- Payment-provider path is currently inactive: There is no active payment provider currently proved. Payment processing or subscription billing resumes only if a future provider is attached to the universal provider-agnostic payment runtime and that checkout path is re-published in current legal materials. While there is no active payment provider currently proved, the only published fallback is a bounded direct/manual path for manual invoicing plus SEPA bank transfer. DepthSignal's own finance/tax system remains the central authority and system of record for payment references, invoice records, refund records, settlement tracking, and VAT/GST monitoring, and any future PSP or bank rail must attach to that internal system as an adapter. This does not by itself prove operational revalidation, self-serve checkout, a current payable path, live card processing, PSP webhooks, generic automated invoice delivery, or settlement execution.
- Resend: transactional email (GDPR Chapter V safeguards; see current DPA Section 9)
- Linear, Inc.: automatic bug report ticket creation and follow-up (GDPR Chapter V safeguards; see current DPA Section 9)
- OpenAI OpCo LLC: AI chat feature, when enabled by the customer (GDPR Chapter V safeguards; see current DPA Section 9)
- Cloudflare: CDN and DDoS mitigation (GDPR Chapter V safeguards; EU nodes for EU traffic)
PostHog analytics is self-hosted on our Hetzner EU infrastructure. PostHog Inc. does not receive customer analytics events, so this does not create a third-party subprocessor transfer.
Hetzner states its datacentre operations are covered by ISO 27001 audited controls. Physical security includes 24/7 staff, CCTV, controlled access, and redundant power and cooling.
The customer-facing API runs in a dedicated network zone, separate from internal data and processing services. Network segmentation and least-privilege service access help reduce blast radius if a component is compromised.
Security and compliance frameworks
We show what is done and what is still in progress. The table below reflects our current state.
GDPR
Controls in placeWe act as data controller. DPA is published. Current self-service rights endpoints cover account/API/usage/security-event/AI-conversation export plus rectification, erasure, and analytics opt-out. Newsletter subscriber export coverage remains an open gap under AF-006 / NC-2026-006. Article 30 records are documented. Breach notification process is in place (72h AKI notification).
Actively maintained
ISO/IEC 27001:2022
PartialWe maintain ISO 27001-aligned internal controls and ISMS artifacts, including policies, quarterly management reviews, a risk register, and a Statement of Applicability. No external ISO 27001 audit or certificate has been completed.
External audit not completed.
SOC 2 Type II
Not startedSOC 2 observation window has not started. Core controls mapped to Trust Service Criteria are in place (access control, monitoring, availability, incident response). Formal SOC 2 audit will start when budget allows.
Observation window planned when ARR justifies cost.
ISO 27001 status means internal control alignment against our Statement of Applicability (ISMS-02). It is not an external audit result.
Controls highlights
Access control
| Customer passwords | We hash passwords with PBKDF2-HMAC-SHA256, 600,000 iterations (NIST SP 800-132). We also check new and reset passwords against known breach data using a k-anonymity API. |
| Two-factor authentication | TOTP (optional for customers; mandatory for all internal company access). |
| Brute-force protection | Automated controls detect brute-force attempts and apply temporary protection when risk is high. |
| API keys | API keys are hashed at rest. The plain key is shown once when created and cannot be recovered later. |
| Internal access | Internal controls are limited to authorized staff with least-privilege access. Sensitive actions require MFA and extra verification. |
| Internal operations log | Security-related internal actions are written to append-only audit records with integrity checks. Retention follows legal and compliance rules. |
Encryption and transport
| Data in transit | External traffic uses TLS (1.2+). HSTS is enabled on supported production endpoints. |
| Certificate management | Automated provisioning and renewal via Let's Encrypt. |
| DDoS / TLS termination | Cloudflare in front of public application endpoints. |
| Customer passwords | Passwords are hashed with PBKDF2-HMAC-SHA256, 600,000 iterations (NIST SP 800-132). |
| API keys | One-way cryptographic hash. Plaintext is not retained after issuance. |
Application security
| Input validation | Core APIs use schema validation with typed models. |
| SQL injection | Production services use parameterized queries and ORM safeguards. |
| Error handling | Generic messages to clients. Stack traces logged server-side only. |
| Automated attack detection | Security middleware and monitoring detect malicious request patterns and apply automated protection. |
| Mandatory code review | Changes to production systems require peer review before deployment. |
| Automated tests | We run automated tests, including end-to-end tests for critical paths. |
Monitoring and incident response
| Service watchdog | We continuously monitor service health with automated recovery and on-call escalation. |
| Breach detection | We run anomaly detection and alerting across authentication, data access, and platform behavior. |
| Security event log | Security events are stored in append-only audit records with integrity controls. Retention follows legal and compliance rules. |
| Incident notification | Personal data breach notification to Estonian DPA (AKI) within 72 hours of becoming aware, per GDPR Article 33. |
Backup and business continuity
| Backup cadence | Automated backups run on a schedule across core data stores and critical app state. |
| Retention | Backup retention follows a documented schedule based on recovery and legal needs. |
| Redundancy | Hetzner-managed infrastructure with automated snapshots independent of the application layer. Encrypted offsite backup expansion in progress. |
| RTO / RPO | Recovery targets are defined, reviewed, and tested in our business continuity process. |
GDPR and data rights
DepthSignal is operated by MarketDepth Analytics OÜ as the customer-facing controller. Ravenna OÜ provides the declared operational data-processing function under contract. The supervisory authority is the Estonian Data Protection Inspectorate (AKI).
Customers can exercise their rights at any time via the platform:
| Right | How to exercise |
|---|---|
| Access (Art. 15) | GET /v1/customer/export - current account/API/usage/security-event/AI-conversation JSON export; newsletter subscriber export remains open under AF-006 / NC-2026-006 |
| Rectification (Art. 16) | PATCH /v1/customer/me |
| Erasure (Art. 17) | DELETE /v1/customer/me - removes live account/API/usage data; billing records and Article 16(m) consent evidence can remain on their own legal-retention basis |
| Portability (Art. 20) | GET /v1/customer/export - machine-readable current account/API/usage/security-event/AI-conversation export; newsletter subscriber export remains open under AF-006 / NC-2026-006 |
| Opt-out of analytics (Art. 21) | POST /v1/customer/me/analytics/opt-out |
Current self-service GDPR-rights endpoints are available for export, rectification, erasure, and analytics opt-out through GET /v1/customer/export, PATCH /v1/customer/me, DELETE /v1/customer/me, and POST /v1/customer/me/analytics/opt-out.
Subprocessors
The subprocessors below cover the current public workflow set. Transfer rules apply where data leaves the EEA. Optional or configuration-dependent providers remain documented in the DPA and current subprocessor records.
| Subprocessor | Purpose | Transfer mechanism |
|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure, compute, storage | EU/EEA (Germany, Finland). No international transfer. |
| Payment-provider path (currently inactive; no active payment provider currently proved) | Payment processing and subscription billing only if a future provider is attached to the universal provider-agnostic payment runtime and a paid checkout path is then activated again. While there is no active payment provider currently proved, the only published fallback is a bounded direct/manual path for manual invoicing plus SEPA bank transfer. DepthSignal's own finance/tax system remains the central authority and system of record for payment references, invoice records, refund records, settlement tracking, and VAT/GST monitoring, and any future PSP or bank rail must attach to that internal system as an adapter. This does not by itself prove operational revalidation, self-serve checkout, a current payable path, live card processing, PSP webhooks, generic automated invoice delivery, or settlement execution. | There is no active payment provider currently proved. The only published fallback while there is no active payment provider currently proved is a bounded direct/manual path for manual invoicing plus SEPA bank transfer. If a future provider is attached to the universal provider-agnostic payment runtime and a payment-provider path is then activated again, its role, region, and transfer basis must be published in the then-current subprocessor and DPA materials before activation. |
| Resend Inc. | Transactional email delivery | GDPR Chapter V safeguards (see current DPA Section 9) |
| Linear, Inc. | Automatic bug report ticket creation and issue follow-up for voluntarily submitted reports | GDPR Chapter V safeguards (see current DPA Section 9) |
| OpenAI OpCo LLC | AI chat feature (when enabled by customer) | GDPR Chapter V safeguards (see current DPA Section 9) |
| Cloudflare Inc. | CDN, DDoS mitigation, TLS termination | GDPR Chapter V safeguards (see current DPA Section 9); EU customers served from EU edge nodes |
Self-hosted analytics note: PostHog software runs on our own EU infrastructure. No PostHog Inc. processor transfer occurs.
We give at least 30 days notice for material subprocessor changes. Requests for additional subprocessor documentation can be sent to [email protected].
Compliance resources
You may contact [email protected]. to request additional security and compliance materials.
For security reasons, the public page is a summary. Detailed evidence is shared under NDA during qualified due diligence.
Assurance artifacts
Teams running formal security review can request a current assurance pack with control summaries, evidence mapping, and process documents for vendor security reviews.
- ISMS control mapping and Statement of Applicability references
- Business continuity and incident response process summaries
- Subprocessor and transfer mechanism documentation.
- Data protection controls, retention rules, and deletion workflow evidence
Responsible disclosure
If you discover a security vulnerability in the DepthSignal platform, report it to [email protected].
Response commitments
- We acknowledge good-faith security reports through the active disclosure workflow after receipt and validation.
- Severity triage and response routing follow the active disclosure workflow after the report is confirmed as in scope.
- Coordinated disclosure timing follows the active disclosure workflow after a valid issue is confirmed.
- We intend to treat good-faith security research that stays within this policy as responsible disclosure rather than abusive use, while reserving the right to take proportionate action to protect users, systems, and legal obligations.
PGP encryption
If you would prefer to submit an encrypted report, email [email protected] to request the current encrypted-report instructions.
Scope
In scope: depthsignal.io, api.depthsignal.io, sentinel.depthsignal.io, and other targets confirmed by our security team. Out of scope: infrastructure not run by MarketDepth Analytics OÜ and third-party subprocessors (Cloudflare, payment providers, etc.).
Full acceptable-use policy: /legal/acceptable-use §4.
Contact
Security review and procurement
For security questionnaires, vendor assessments, or procurement due diligence, contact [email protected]. DPA requests and legal correspondence should be sent to [email protected].
Security issues
[email protected] (vulnerability reports and security questions only).
Legal and data protection
[email protected] (DPA requests, GDPR rights, legal correspondence).
MarketDepth Analytics OÜ
Registry code: 17549629 · Estonia
This document is reviewed at least annually. For the most current version, contact [email protected].