Trust Center

Security, AI governance and operational transparency.

Ballad Markets develops its security, AI-governance and quality-management practices against internationally recognised frameworks. Every status on this page is backed by our code or our records — and where it isn't yet, the page says so.

Aligned with, not certified by. No accredited body has audited Ballad Markets. ISO/IEC 27001, ISO/IEC 42001 and ISO 9001 are the frameworks we document our practices against.

How to read the markers✓Implemented◐Partially implemented○Planned⚠Requires verification

Information security

ISO/IEC 27001 aligned

We keep documented practices for information security, access control, secrets management, data protection, incident response, business continuity and risk management. This is where each one stands today.

  • ✓

    Broker keys encrypted

    Exchange and broker API keys are encrypted with AES-256-GCM before storage and decrypted only in memory, per request.

  • ✓

    No withdrawal access

    A key that carries withdrawal permission is rejected and deleted at validation. Stored connections are re-checked against the broker every four hours.

  • ✓

    Per-account data isolation

    Row-level security in the database: each account can read only its own records.

  • ✓

    Server-side authentication

    Sessions are validated on the server for every protected route; sign-in and checkout are rate-limited.

  • ✓

    Transport and browser security

    HTTPS everywhere with HSTS preload, a Content Security Policy and hardened security headers.

  • ✓

    Secret scanning and dependency gate

    Every code change to production — and the full history, daily — is scanned for leaked credentials; an unreviewed critical advisory fails the check.

  • ✓

    Monitoring and alerting

    Heartbeats on every scheduled job, dependency health checked by content rather than status code, and alerts to an operations channel.

  • ◐

    Incident response

    A written process: contain, fix the root cause, prove the fix with a test, record what happened. Formal drills are not yet run.

  • ◐

    Access control on production

    Blocking checks guard the production branch today. Stronger review rules on that branch are being added.

  • ◐

    Business continuity

    Failure scenarios and fallbacks are documented; recovery objectives are set but not yet tested.

  • ⚠

    Backup restore

    Database backups are managed by our hosting provider. A restore test has not yet been recorded.

  • ○

    Independent penetration test

    Not yet performed. We will not describe the platform as audited until it has been.

Report a vulnerability

Found a security issue? Tell us privately, give us time to fix it, and we will work with you on it.

  1. 1

    Email support@balladmarkets.com with [SECURITY] in the subject line.

  2. 2

    Include the affected component, what you found, steps to reproduce, the impact you observed, any evidence, and a mitigation if you have one.

  3. 3

    Never send passwords, API keys, private keys, personal data or production credentials — ours or anyone else's.

  4. 4

    Test only against your own account. Do not place orders, move funds, disrupt the service or access another user's data.

Our response targets

Acknowledgement
3 business days
Initial assessment
10 business days
Fix target, critical issues
30 days

Internal targets, not contractual guarantees.

Machine-readable contact: /.well-known/security.txt

Supply-chain security

OpenSSF Scorecard — automated security assessment

Runs every week on our source repository and checks branch protection, pinned dependencies, token permissions and dangerous workflow patterns. The repository is private, so the score is not published — and we will not show a number you cannot check.

  • ✓

    Weekly Scorecard analysis

    Report kept with each run for review.

  • ✓

    Automated dependency updates

    Web app, workers, desk and CI dependencies, grouped weekly or monthly.

  • ✓

    Secret scanning

    Working tree and history, blocking.

  • ◐

    Actions pinned to exact commits

    New workflows pin every action to a commit; older ones are being migrated.

Responsible AI

ISO/IEC 42001 aligned

Every AI system that exists in our code is registered — what it does, what it can and cannot do, and who oversees it. We document:

  • AI systems
  • AI agents
  • AI risks
  • Human oversight
  • Model evaluation
  • Data governance
  • Output validation
  • Agent changes
  • Incidents
  • Continuous improvement

A model advises; rules decide.

No model output places an order unless it passes fixed rules the model cannot change: minimum conviction, sector and cash limits, the risk mode.

Shadow before live.

New decision logic runs silently first and is switched on only by an explicit owner decision after a dated review.

Every report is traceable.

Each desk report is stored with the code version, a fingerprint of the prompts and the risk mode that produced it.

Paper is labelled paper.

Desk results come from a paper brokerage account and are shown as such. We do not advertise performance percentages.

AI agent registry

SystemWhat it doesPlaces orders?Human oversight
CHESKO 2.0Multi-agent research desk: analyses a watchlist, debates each case and sizes positions within risk limits.Yes — on the desk's own paper account. Followers receive copies only under their own settings and consent.Conviction gate, risk limits, kill switch, owner-controlled arming of new logic.
SPIKEReads a chart image, extracts the trade plan and scores it — or declines when it cannot read it.NoAdvisory: the user decides.
Darwin chatAnswers questions about Darwin's technical read of a market.NoInformational only.
Support assistantGives a first answer to support messages.NoEmail to support reaches a person.
Market briefWrites the daily market brief from news sources.NoRefuses to publish without sources.
TRUMP LIVEClassifies political headlines by market relevance.NoIntelligence only — no trading.
Internal toolsDraft marketing content and help screen affiliate activity.NoContent is published only with owner approval.

Not AI. DELIA (order execution), Darwin's technical core, the market scanners and the trailing-stop policy run on fixed rules and formulas. No model decides there.

Quality management

ISO 9001 aligned

We document how software is developed, tested, released, changed and corrected — and how we listen to the people who use it.

  • ✓

    Automated quality gate

    Type-checking, lint and unit tests run on every change to the production branch and fail loudly. Making them a hard requirement before release is on the roadmap.

  • ✓

    Controlled releases

    No production deploys during the trading desk's session window; a daily check flags production running behind.

  • ✓

    Corrective action with proof

    Every fix ships with a test that fails without it; nonconformities are recorded with their root cause.

  • ✓

    Change control for trading logic

    Anything that can move an order runs in shadow first and is enabled by an explicit decision.

  • ◐

    Customer feedback

    Every message to support reaches a person; response-time targets are not yet published.

  • ○

    End-to-end testing

    A browser-level test suite is not yet in place.

Risk management

We keep a central risk register: every risk scored by probability × impact, with an owner and a next action, reviewed monthly and after any incident. Where we lack the evidence to score a risk honestly, it is marked as requiring assessment instead of guessed.

Before we pursue any certification

  • ○An independent penetration test
  • ○A recorded database restore test
  • ○A second administrator on critical accounts
  • ○Review rules on the production branch
  • ○An external readiness assessment

Documentation

Public

Internal

  • Security policy and disclosure process
  • Information-security management — 15 documents, incl. the statement of applicability
  • AI management — 13 documents, incl. the AI agent registry
  • Quality management — 11 documents
  • Central risk register
  • Security architecture

Kept in our private repository. Partners and auditors can request access at support@balladmarkets.com.