Skip to main content
Trust & security

Zero-trust architecture, deployed where you decide

Security is designed in at every layer: encrypted data and tokenized identifiers at the core, clearance-aligned access around it, deployment on infrastructure you control, and continuous audit over every action.

Deployment options
AuditContinuous monitoring & loggingNetworkAir-gapped · GovCloud · hybridAccessMFA · RBAC by clearanceWorkspace isolationHard-walled on every queryDataAES-256 encryptionPII token vault
Platform security

Defense in depth, by design

  • AES-256 encryptionData encrypted at rest and in transit.
  • Multi-factor authenticationEnforced second factor, with PIV/CAC card and biometric options for government users.
  • Role-based access controlGranular permissions aligned with clearance levels and need-to-know.
  • Air-gapped deploymentDeployable inside isolated networks with no outbound dependency.
  • PII token vaultSensitive identifiers tokenized with retention policies, and every detokenization logged.
  • Hard-walled workspacesBanking and insurance data never mix, with isolation enforced on every query and API key.
  • Tamper-evident audit trailEvery consequential action is logged and attributable.
  • Cloud securityPosture management, workload protection and secure architecture across AWS, Azure and government cloud regions.
Frameworks

Designed to support the frameworks you answer to

The platform and our services are built to help clients meet these frameworks. Formal certifications and attestations are client- and deployment-specific; we provide our current documentation on request.

NIST SP 800-53
Control baseline for US federal systems
NIST CSF
Program structure for security operations
ISO/IEC 27001
Information security management
SOC 2
Service organization controls
CJIS Security Policy
US criminal justice information
POPIA
South African personal information
GDPR
EU personal data
FIC Act
South African AML/CFT obligations
PCI DSS
Payment card data
Deployment options

Flexible architecture for any environment

On-premises

Deploy within your secure facilities with complete control over data and infrastructure.

  • Air-gapped network support
  • Isolated-network configurations
  • Custom hardware integration

Government cloud

Run in government cloud regions for scalability with sovereign controls.

  • AWS GovCloud and Azure Government supported
  • In-country cloud providers
  • Automated compliance reporting

Hybrid

Combine on-premises and cloud deployments for flexibility without giving up control.

  • Sensitive holdings kept on-premises
  • Selective data synchronization
  • Unified management console
AI governance

AI that works for analysts, under control

Tokenized identifiers

Sensitive identifiers are tokenized in the PII vault with retention policies, and every detokenization is logged against the person who requested it.

Structured products, not chat

Assessments produce typed outputs such as threat level, entities, narratives and recommended actions, each traceable to its sources.

Humans approve consequential actions

Counter-disinformation responses are transparent, published from official accounts and approved by people. Automation never moves money.

Every action audited

AI requests and analyst decisions are written to a tamper-evident audit trail, attributable to a named user.

Responsible disclosure

Report a vulnerability

If you believe you have found a security issue in this website or our platform, please report it through the contact form with the enquiry type “Other” and the word “Security” in your message. We acknowledge reports, keep you informed and will not pursue good-faith research that avoids privacy violations and service disruption. Our machine-readable policy is published at /.well-known/security.txt.

Get started

Take the next step

Review our security posture, documentation and deployment architecture with our team: on-premises, government cloud or hybrid.

About Dark Pools