Request Audit Pack
Security & Compliance Trust Center

Your Trade Data, Under Your Control

Bank-grade encryption. Granular access controls. SOC 2, GDPR, ISO 27001 alignment. Full deployment flexibility β€” including on-premise and air-gapped environments.

πŸ”
AES-256 Encryption
πŸ›‘οΈ
SOC 2 Type II
🌍
GDPR Compliant
🏒
Self-Hosted

Defense-in-Depth Security Architecture

Seven layers of protection across infrastructure, application, data, and operations.

Encryption Everywhere

All data is protected with industry-standard encryption, both at rest and in transit.

  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest
  • Bring Your Own Key (BYOK) on Enterprise
  • Hardware Security Module (HSM) support
  • Encrypted backups with separate key custody

Identity & Access Control

Granular, role-based access with full audit trails and zero-trust principles.

  • Role-Based Access Control (RBAC)
  • SSO / SAML 2.0 / OIDC integration
  • Multi-Factor Authentication (MFA/TOTP/WebAuthn)
  • IP allowlisting and geo-fencing
  • Session timeout and device management
  • Just-in-Time access provisioning

Data Residency & Sovereignty

Choose where your data lives. Full control over cross-border data flows.

  • Regional cloud: US, EU, Singapore, Middle East
  • On-premise deployment (Linux/Windows/K8s)
  • Air-gapped / offline environments supported
  • No outbound calls β€” zero telemetry required
  • Customer-controlled data export (CSV/JSON/API)

Audit & Compliance

Complete audit trails and immutable logs for regulatory compliance.

  • Immutable audit logs (tamper-evident)
  • Full activity history per user, document, transaction
  • SIEM integration (Splunk, ELK, Datadog)
  • Quarterly third-party penetration testing
  • Annual SOC 2 Type II audit
  • GDPR data processing agreements (DPA)

Application Security

Built with security-first development practices.

  • OWASP Top 10 protection by default
  • Regular dependency scanning (Snyk/Trivy)
  • SQL injection, XSS, CSRF protections
  • Content Security Policy (CSP) headers
  • Rate limiting and DDoS protection
  • Secure Software Development Lifecycle (SDLC)

Reliability & Resilience

Your trade operations cannot afford downtime.

  • 99.95% uptime SLA (Enterprise tier)
  • Multi-region active-active failover
  • Point-in-time recovery (PITR)
  • Daily backups, 35-day retention
  • Disaster recovery runbooks tested quarterly
  • Status page at status.p9p9.top

Compliance & Certifications

We meet the standards your auditors and customers expect.

Standard / Regulation Status Applies To Notes
GDPR (EU General Data Protection Regulation)βœ“ CompliantAll customersDPA available on request
CCPA / CPRA (California Consumer Privacy)βœ“ CompliantAll customersData subject access request workflow
SOC 2 Type IIβœ“ AuditedCloud SaaSAnnual audit, report under NDA
ISO 27001⟳ In progressCloud SaaSTarget Q4 2026 certification
ISO 27017 (Cloud Security)⟳ In progressCloud SaaSTarget Q4 2026
ISO 27018 (Cloud Privacy)⟳ In progressCloud SaaSTarget Q4 2026
HIPAANot applicableHealthcareOut of scope for trade platform
PCI DSSOut of scopePaymentsWe don't process card data; integrated with Stripe/PayPal
Data Localization (China PIPL, Russia, India DPDP)βœ“ Self-hosted availableSelf-hosted deploymentsCustomer-operated infrastructure

Deployment Architecture

Same product, four deployment models. Choose based on your data sovereignty, compliance, and IT strategy.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ GlobalTradePro Platform β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ Cloud SaaS β”‚ β”‚ Private Cloud β”‚ β”‚ On-Premise β”‚ β”‚ β”‚ β”‚ (Multi-tenant) β”‚ β”‚ (Single-tenant) β”‚ β”‚ (Customer HW) β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β€’ AWS/Azure/GCP β”‚ β”‚ β€’ Your VPC β”‚ β”‚ β€’ Your DC β”‚ β”‚ β”‚ β”‚ β€’ Shared cluster β”‚ β”‚ β€’ Dedicated pods β”‚ β”‚ β€’ Air-gapped β”‚ β”‚ β”‚ β”‚ β€’ Managed by us β”‚ β”‚ β€’ You control β”‚ β”‚ β€’ You control β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ Edge Layer / WAF / DDoS Protection β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ Application Layer (Microservices, REST API, Workers) β”‚ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ β”‚ β”‚ Auth & β”‚ β”‚Contract β”‚ β”‚ Supply β”‚ β”‚ Order Tracking β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ RBAC β”‚ β”‚ Mgmt β”‚ β”‚ Chain β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ Data Layer (Encrypted, Replicated) β”‚ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ β”‚ β”‚ PostgreSQL β”‚ β”‚ Object β”‚ β”‚ Encrypted β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ (Primary) β”‚ β”‚ Storage β”‚ β”‚ Backups β”‚ β”‚ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Responsible Disclosure

We welcome security researchers. If you discover a vulnerability, please report it responsibly.

Report a Vulnerability

Send findings to security@p9p9.top with PGP encryption (key on request). We commit to:

  • Acknowledgement within 24 hours
  • Initial assessment within 72 hours
  • Coordinated disclosure timeline agreed within 7 days
  • Public credit (with permission) in our security hall of fame

Scope: *.p9p9.top, official mobile apps, public APIs. Out of scope: social engineering, physical attacks, DoS testing.

Need Our Security Audit Pack?

Get our SOC 2 report, penetration test summary, architecture diagrams, DPA, and security questionnaire answers under NDA. Available to qualified prospects and customers.

Request Audit Pack