Security, AI governance and operational transparency.
Ballad Markets develops its security, AI-governance and quality-management practices against internationally recognised frameworks. Every status on this page is backed by our code or our records — and where it isn't yet, the page says so.
Information security
ISO/IEC 27001 aligned
✓Framework established
AI governance
ISO/IEC 42001 aligned
✓Framework established
Quality management
ISO 9001 aligned
✓Framework established
Aligned with, not certified by. No accredited body has audited Ballad Markets. ISO/IEC 27001, ISO/IEC 42001 and ISO 9001 are the frameworks we document our practices against.
Information security
ISO/IEC 27001 alignedWe keep documented practices for information security, access control, secrets management, data protection, incident response, business continuity and risk management. This is where each one stands today.
- ✓
Broker keys encrypted
Exchange and broker API keys are encrypted with AES-256-GCM before storage and decrypted only in memory, per request.
- ✓
No withdrawal access
A key that carries withdrawal permission is rejected and deleted at validation. Stored connections are re-checked against the broker every four hours.
- ✓
Per-account data isolation
Row-level security in the database: each account can read only its own records.
- ✓
Server-side authentication
Sessions are validated on the server for every protected route; sign-in and checkout are rate-limited.
- ✓
Transport and browser security
HTTPS everywhere with HSTS preload, a Content Security Policy and hardened security headers.
- ✓
Secret scanning and dependency gate
Every code change to production — and the full history, daily — is scanned for leaked credentials; an unreviewed critical advisory fails the check.
- ✓
Monitoring and alerting
Heartbeats on every scheduled job, dependency health checked by content rather than status code, and alerts to an operations channel.
- ◐
Incident response
A written process: contain, fix the root cause, prove the fix with a test, record what happened. Formal drills are not yet run.
- ◐
Access control on production
Blocking checks guard the production branch today. Stronger review rules on that branch are being added.
- ◐
Business continuity
Failure scenarios and fallbacks are documented; recovery objectives are set but not yet tested.
- ⚠
Backup restore
Database backups are managed by our hosting provider. A restore test has not yet been recorded.
- ○
Independent penetration test
Not yet performed. We will not describe the platform as audited until it has been.
Report a vulnerability
Found a security issue? Tell us privately, give us time to fix it, and we will work with you on it.
- 1
Email support@balladmarkets.com with [SECURITY] in the subject line.
- 2
Include the affected component, what you found, steps to reproduce, the impact you observed, any evidence, and a mitigation if you have one.
- 3
Never send passwords, API keys, private keys, personal data or production credentials — ours or anyone else's.
- 4
Test only against your own account. Do not place orders, move funds, disrupt the service or access another user's data.
Our response targets
- Acknowledgement
- 3 business days
- Initial assessment
- 10 business days
- Fix target, critical issues
- 30 days
Internal targets, not contractual guarantees.
Machine-readable contact: /.well-known/security.txt
Supply-chain security
OpenSSF Scorecard — automated security assessment
Runs every week on our source repository and checks branch protection, pinned dependencies, token permissions and dangerous workflow patterns. The repository is private, so the score is not published — and we will not show a number you cannot check.
- ✓
Weekly Scorecard analysis
Report kept with each run for review.
- ✓
Automated dependency updates
Web app, workers, desk and CI dependencies, grouped weekly or monthly.
- ✓
Secret scanning
Working tree and history, blocking.
- ◐
Actions pinned to exact commits
New workflows pin every action to a commit; older ones are being migrated.
Responsible AI
ISO/IEC 42001 alignedEvery AI system that exists in our code is registered — what it does, what it can and cannot do, and who oversees it. We document:
- AI systems
- AI agents
- AI risks
- Human oversight
- Model evaluation
- Data governance
- Output validation
- Agent changes
- Incidents
- Continuous improvement
A model advises; rules decide.
No model output places an order unless it passes fixed rules the model cannot change: minimum conviction, sector and cash limits, the risk mode.
Shadow before live.
New decision logic runs silently first and is switched on only by an explicit owner decision after a dated review.
Every report is traceable.
Each desk report is stored with the code version, a fingerprint of the prompts and the risk mode that produced it.
Paper is labelled paper.
Desk results come from a paper brokerage account and are shown as such. We do not advertise performance percentages.
AI agent registry
| System | What it does | Places orders? | Human oversight |
|---|---|---|---|
| CHESKO 2.0 | Multi-agent research desk: analyses a watchlist, debates each case and sizes positions within risk limits. | Yes — on the desk's own paper account. Followers receive copies only under their own settings and consent. | Conviction gate, risk limits, kill switch, owner-controlled arming of new logic. |
| SPIKE | Reads a chart image, extracts the trade plan and scores it — or declines when it cannot read it. | No | Advisory: the user decides. |
| Darwin chat | Answers questions about Darwin's technical read of a market. | No | Informational only. |
| Support assistant | Gives a first answer to support messages. | No | Email to support reaches a person. |
| Market brief | Writes the daily market brief from news sources. | No | Refuses to publish without sources. |
| TRUMP LIVE | Classifies political headlines by market relevance. | No | Intelligence only — no trading. |
| Internal tools | Draft marketing content and help screen affiliate activity. | No | Content is published only with owner approval. |
Not AI. DELIA (order execution), Darwin's technical core, the market scanners and the trailing-stop policy run on fixed rules and formulas. No model decides there.
Quality management
ISO 9001 alignedWe document how software is developed, tested, released, changed and corrected — and how we listen to the people who use it.
- ✓
Automated quality gate
Type-checking, lint and unit tests run on every change to the production branch and fail loudly. Making them a hard requirement before release is on the roadmap.
- ✓
Controlled releases
No production deploys during the trading desk's session window; a daily check flags production running behind.
- ✓
Corrective action with proof
Every fix ships with a test that fails without it; nonconformities are recorded with their root cause.
- ✓
Change control for trading logic
Anything that can move an order runs in shadow first and is enabled by an explicit decision.
- ◐
Customer feedback
Every message to support reaches a person; response-time targets are not yet published.
- ○
End-to-end testing
A browser-level test suite is not yet in place.
Risk management
We keep a central risk register: every risk scored by probability × impact, with an owner and a next action, reviewed monthly and after any incident. Where we lack the evidence to score a risk honestly, it is marked as requiring assessment instead of guessed.
Before we pursue any certification
- ○An independent penetration test
- ○A recorded database restore test
- ○A second administrator on critical accounts
- ○Review rules on the production branch
- ○An external readiness assessment
Documentation
Internal
- Security policy and disclosure process
- Information-security management — 15 documents, incl. the statement of applicability
- AI management — 13 documents, incl. the AI agent registry
- Quality management — 11 documents
- Central risk register
- Security architecture
Kept in our private repository. Partners and auditors can request access at support@balladmarkets.com.