Introduction
Uliaa is a technology platform for exploring investment ideas, developing strategies, publishing financial content and managing portfolios through a secure, connected environment. It utilises a spectrum of software and hardware systems, including:
- cloud hosting and infrastructure;
- databases and data stores;
- file storage systems;
- financial market networks;
- third-party data providers;
- identity-verification services;
- other trusted third-party systems; and
- the public internet.
Given the diversity of these systems, Uliaa recognises that security incidents or misuse could affect our customers’ personal information, financial security, business operations and infrastructure. We therefore take a layered approach to protecting the platform and the systems connected to it.
For these reasons, Uliaa is committed to protecting the security of our customers’ information and connected systems. We follow recognised security practices, apply appropriate technical and organisational safeguards, and regularly review our policies, controls and infrastructure as the threat landscape evolves.
Overview
Uliaa’s security vision is built around a layered strategy that protects infrastructure and data throughout access, transfer, processing and storage. Our controls are designed to adapt to each customer’s circumstances, policies and applicable requirements across different jurisdictions. This strategy comprises the following ten components:
- Uliaa corporate security policy;
- organizational security;
- information classification and control policy;
- privacy policy;
- physical and environmental security;
- operational security;
- access control;
- system development and maintenance;
- disaster recovery and business continuity;
- regulatory compliance.
Corporate Security Policies
Uliaa is committed to protecting the infrastructure accessed or managed by its software, together with the information stored and processed through its systems. This commitment is supported by a comprehensive set of security policies covering physical security, identity and access management, data protection and privacy, corporate services, networks, systems and infrastructure, change management, incident response, data handling and retention. We review these policies regularly to ensure they remain effective, accurate and aligned with current risks, technologies and regulatory expectations.
All Uliaa employees and consultants must understand and comply with these policies. They are supported by practical security guidance covering topics such as safe internet use, remote working, information classification, and the identification and handling of sensitive information.
Organizational Security
Uliaa maintains a dedicated security and platform operations function responsible for developing, documenting and implementing the organisation’s security policies, standards and operational controls. The team oversees the security of Uliaa’s systems and services, maintains the platform’s perimeter protections, coordinates security reviews and develops safeguards appropriate to the platform’s architecture and risk profile.
The team’s activities include:
- developing and continuously reviewing security plans for Uliaa’s networks, systems and services through a rigorous, multi-phase process;
- conducting regular security architecture, design and implementation reviews;
- reviewing new Uliaa system deployments and material changes to customer-facing infrastructure;
- providing ongoing guidance on security risks, mitigations and control improvements, including alerts and updates on newly identified threats and relevant security practices;
- monitoring Uliaa systems and networks for suspicious activity and following documented incident-response procedures to identify, investigate, contain and remediate security events;
- monitoring platform health and responding to faults or conditions that could affect service availability or business continuity;
- designing and implementing technical safeguards to reduce the likelihood and potential impact of security incidents and operational failures;
- assessing compliance with Uliaa’s security policies through routine reviews, control testing and internal audits; and
- engaging suitably qualified independent security specialists to conduct periodic assessments of Uliaa’s software, infrastructure and operational practices.
Information Classification and Control
Uliaa classifies information according to its sensitivity, business value, privacy implications and potential impact if it is accessed, changed or disclosed without authorisation. The classification determines how information must be handled, where it may be stored, who may access it and what safeguards must be applied. All information handled by Uliaa personnel or stored in Uliaa systems is assigned to one of the following four classifications:
Public information may be shared freely because its disclosure is not expected to cause harm to Uliaa or its customers. This includes publicly available website content, published product information and other material expressly approved for public distribution.
Proprietary information is intended primarily for internal use. It may be shared with customers, suppliers or other external parties only where there is a legitimate business purpose and the information owner has authorised the disclosure. Examples include software distributions, internal processes, product documentation and non-public business information.
Restricted information requires controlled access because unauthorised disclosure could affect Uliaa, its customers or its business relationships. Access is limited to people who need the information for an approved purpose, and broader disclosure requires explicit authorisation from the information owner. Customer information, information relating to prospective transactions and commercially sensitive operational data are generally treated as restricted.
Confidential information is information whose unauthorised access or disclosure could cause significant harm to Uliaa, its customers or another party. Examples include credentials, security certificates, encryption keys, sensitive financial information, personal information and strategic business documents. Access must be individually authorised and limited to those with a clear business need.
Unless there is a documented reason to assign information to another classification, newly created or received information is initially treated as Restricted. Information owners are responsible for reviewing classifications as circumstances change and for ensuring that appropriate access, handling, retention and disposal controls are applied.
Privacy Policy
Uliaa collects and uses personal information to provide, secure and improve its products and services, meet legal and regulatory obligations, and communicate with users about their relationship with Uliaa. The information we collect may include account details, contact information, identity-verification data, financial information and records of activity on the platform.
We collect only the information we need for these purposes, handle it in accordance with applicable privacy laws, and apply appropriate access controls, encryption and other safeguards. We do not use personal information for marketing or share it with third parties without your permission, except where required or authorised by law or necessary to provide a requested service.
Our Privacy Policy explains how we collect, use, store, retain and protect personal information, as well as how you can access or correct your information, withdraw consent and raise a privacy concern.
View the full Privacy Policy →
Data Retention
Uliaa retains information only for as long as it is needed for legitimate business, security, legal or regulatory purposes. The following are Uliaa’s standard minimum retention periods:
Seven Years
- personal information;
- other customer information;
- transaction and trading records, including orders, approvals and execution history;
- financial and accounting records, including invoices, payments and creator fees;
- identity-verification and compliance records;
- consent, permissions and privacy requests;
- security and access records, including authentication events and incident records;
- audit and change-management records;
- legal holds, disputes and investigation records; and
- backups.
Three Years
- support and enquiry communications; and
- user-generated content and strategy records.
One Year
- log files; and
- other operating data.
Where applicable law requires a longer or shorter retention period in a specific jurisdiction, the regulation-prescribed period applies. Retention periods may also be extended where information is subject to a legal hold, an active investigation, a dispute or another documented business requirement. When information is no longer required, Uliaa securely deletes, destroys or anonymises it in accordance with its classification and the capabilities of the relevant system.
Physical and Environmental Security
Uliaa requires operational and business systems to run in appropriately secured physical environments, including accredited and professionally managed data centres and other facilities with controlled access to servers, networking equipment and supporting infrastructure. Physical access must be restricted to authorised personnel, with appropriate environmental protections for power, cooling, fire, water, equipment failure and other conditions that could affect the availability or integrity of systems.
Where operational requirements mean that non-public information must travel across shared or otherwise less-controlled infrastructure, including the public internet or a customer’s local network, Uliaa applies appropriate cryptographic protections to preserve the confidentiality and integrity of that information in transit. Uliaa also maintains logical separation between customers and does not permit one customer’s information to be transmitted, stored or processed through another customer’s infrastructure except where explicitly authorised and appropriately protected.
Operational Security
Network Security
Uliaa uses layered network protections to defend its cloud infrastructure, services and connected systems against unauthorised access, abuse and disruption. Network access follows a deny-by-default model: only approved services, protocols and connections are permitted, and access is limited to the minimum required for each system’s purpose. Network boundaries are segmented according to trust level and function, with administrative and service access subject to explicit authentication, authorisation and ongoing monitoring.
Uliaa applies encryption using current industry-standard transport protocols and manages cryptographic keys through controlled processes. Internet-facing services are protected with appropriate edge controls, including traffic filtering, rate limiting and protections against common application and network attacks. Security-relevant events are logged centrally and monitored to support threat detection, investigation and incident response. Network configurations, access rules and connected services are reviewed regularly, including when systems change or new third-party integrations are introduced.
Uliaa’s approved network encryption standards include TLS 1.3, with TLS 1.2 permitted where required for interoperability and configured only with approved cipher suites; SSH Protocol 2 for secure administration and file transfer; and IPsec with IKEv2 for protected network-to-network connections. Mutual TLS may be used where service-to-service authentication is required. Deprecated protocols and algorithms, including SSL, TLS 1.0 and 1.1, obsolete SSH versions, weak ciphers and unauthorised cryptographic configurations, must not be used.
Where a particular component cannot support an approved encryption standard because of a documented technical constraint, the required level of encryption may be relaxed only through a formal waiver approved by the CTO. The waiver must record the reason, scope, duration and review date, and must identify alternative safeguards that provide equivalent protection as far as practicable.
Operating System Security
Uliaa configures operating systems and host environments according to hardened security baselines appropriate to their role, operating environment and risk profile. Systems are provisioned with only the software, services, ports and privileges required for their intended purpose, and unnecessary components are disabled or removed. Production workloads are logically isolated where appropriate, with administrative access restricted, strongly authenticated and recorded.
Operating systems, packages, libraries and security tools are maintained through a managed patching process. Security updates are assessed according to severity and exposure, prioritised for remediation and applied within defined timeframes. System configurations are regularly reviewed to detect drift from approved baselines, and material changes are subject to controlled deployment and rollback procedures.
Uliaa uses host-based monitoring and file-integrity controls, or equivalent safeguards appropriate to the environment, to identify unauthorised changes, suspicious processes and other indicators of compromise. Alerts are routed to the security and platform operations function for investigation and response. Where supported by the environment, endpoint protection, malware prevention and threat-detection capabilities are maintained with current signatures, detection models and policy updates. System logs are retained and protected in accordance with Uliaa’s logging, monitoring and retention requirements.
Monitoring
Uliaa maintains continuous monitoring across its networks, cloud infrastructure, services and security-relevant systems. Monitoring combines system and application metrics, centralised logs, security events, performance signals and operational alerts to identify abnormal activity, service degradation, unauthorised access and other indicators of risk. Alerts are prioritised according to severity and potential impact, with relevant events investigated and escalated through Uliaa’s incident-response processes.
Uliaa regularly reviews security advisories, threat intelligence and vulnerability information relevant to its technologies and service providers. Monitoring configurations, detection rules and alert thresholds are reviewed and updated as systems and threats evolve. Security logs and monitoring records are protected against unauthorised alteration and retained in accordance with Uliaa’s Data Retention policy. Uliaa also commissions periodic independent assessments of its software, infrastructure and security controls.
Incident Response
Uliaa maintains documented incident-response procedures for identifying, assessing and managing security incidents affecting its systems, services, information or customers. Security events are recorded, triaged according to severity and potential impact, and escalated to the appropriate technical, operational, legal and leadership teams. Response activities may include investigation, containment, eradication, service restoration, evidence preservation and communications with affected parties or authorities where required.
Following a material incident, Uliaa conducts a post-incident review to identify contributing factors, assess the effectiveness of the response and implement corrective actions. Incident-response procedures, contact paths and recovery processes are tested and updated periodically to reflect changes in the platform, threat environment and regulatory requirements.
Vulnerability Management
Uliaa maintains a vulnerability-management programme covering its applications, infrastructure, dependencies, cloud services and other technology assets. Vulnerabilities may be identified through automated scanning, dependency and configuration analysis, code review, security testing, penetration testing, threat intelligence, external assessments and reports from responsible researchers.
Confirmed vulnerabilities are recorded, assessed and prioritised according to factors including severity, exploitability, exposure, affected data or services and potential business impact. Each remediation item is assigned to an accountable owner, tracked through to resolution and subject to defined remediation timeframes. Fixes are validated through testing or rescanning before the vulnerability is closed.
Uliaa also monitors relevant vendor and open-source security advisories, maintains visibility of material software components and dependencies, and reviews emerging threats that may affect the platform. Where immediate remediation is not practicable, the risk must be documented, approved by an appropriate authority, monitored and supported by compensating safeguards. Vulnerability-management processes are reviewed regularly to improve coverage, prioritisation and response effectiveness.
Use of Resources
Uliaa’s security and service reliability depend on the responsible use of its networks, systems, devices and third-party services. All employees, contractors and other authorised users must use Uliaa resources lawfully, ethically and in accordance with Uliaa’s security policies. Access is provided for approved business purposes and must not be shared, transferred or used to bypass security controls.
Users must not introduce malware or unauthorised software, disclose credentials, use unapproved storage or collaboration services for sensitive information, conduct unauthorised scanning or testing, mine cryptocurrency, operate unauthorised servers, participate in abusive or fraudulent activity, distribute unlawful or infringing material, or engage in conduct that could compromise Uliaa, its customers, its service providers or the wider internet. Users must also avoid activities that create unreasonable load, degrade service availability or consume resources needed for customers and other authorised users.
Uliaa may monitor the use of its systems and network resources for security, operational, compliance and incident-response purposes, subject to applicable law and the Privacy Policy. Suspected misuse must be reported promptly. This policy is reviewed regularly to reflect changes in technology, threats, legal obligations and accepted security practice.
Access Control
Authentication Controls
Uliaa assigns a unique identity and account to every employee, contractor, customer and other authorised user. Accounts and authentication rights are managed through a central LDAP identity-management server. Account credentials and authentication factors must never be shared, transferred or reused by different people. These requirements apply equally to Uliaa personnel and customer accounts.
Authentication activity is attributable to a specific user, allowing Uliaa to maintain accountability for actions performed across its systems. Passwords and passphrases must meet Uliaa’s strength requirements and may not be reused inappropriately.
Where multi-factor authentication is required, Uliaa uses phishing-resistant external USB security keys based on modern public-key authentication standards, such as FIDO2/WebAuthn, wherever the device and service support them. Where a security key cannot be used, SMS-based one-time codes may be used as a fallback. SMS authentication is treated as a lower-assurance option and should be replaced with a stronger method whenever practical.
Uliaa uses RSA public-key infrastructure for certificate-based authentication and secure system operations. RSA certificates are not treated as a second authentication factor. Operating certificates are at least 2048 bits and are rotated annually. Root certificates are 4096 bits and are rotated every ten years, or sooner where required by risk, compromise or operational necessity.
When a user joins Uliaa or is granted access, permissions are assigned according to their role and approved business requirements. Access is revoked promptly when it is no longer required, including when employment, engagement or customer access ends. Account records and associated activity histories are retained in accordance with Uliaa’s Data Retention policy.
Every material data change made in Uliaa’s systems is associated with the specific user responsible for the change. These records form part of the system audit trail and are retained and protected in accordance with Uliaa’s Data Retention policy.
Authorization Controls
Uliaa uses fine-grained, least-privilege authorisation controls to determine which users, services and administrators may access specific resources or perform particular actions. Permissions are denied by default and granted only where required for an approved business purpose. Access rights can be granted, modified and revoked independently for individual resources, services and operations.
Customer access is protected through tenant isolation and a hierarchical, fine-grained permission model. A user’s effective permissions cannot exceed those granted to the relevant customer organisation, and organisation-level permissions cannot exceed the boundaries established by Uliaa. Resource owners and authorised customer administrators may manage access within those boundaries.
Privileged access is restricted to authorised personnel, separately controlled and monitored. Permissions are reviewed periodically, adjusted when roles or responsibilities change, and revoked promptly when access is no longer required. Authorisation decisions and material permission changes are recorded in the audit trail and retained under Uliaa’s Data Retention policy.
Logging and Accountability
Uliaa maintains audit records that support accountability, traceability and investigation across its production systems. Audit records capture administrative access, authentication events, authorisation decisions, material data changes, permission changes, configuration changes, security events and other actions that could affect the confidentiality, integrity or availability of systems and information.
Where technically practicable, each record identifies the user or service responsible, the resource and action involved, the time and outcome of the action, and the relevant source or session. System clocks are synchronised so that events can be correlated reliably across services.
Audit records are centralised or otherwise protected against unauthorised alteration and are accessible only to authorised personnel. Monitoring rules may generate alerts for unusual, high-risk or unauthorised activity. Records are reviewed periodically and when required for security investigations, incident response, compliance activities or customer enquiries, and are retained in accordance with Uliaa’s Data Retention policy.
System Development and Maintenance
Uliaa integrates security throughout the software and systems lifecycle. Security requirements are considered during product planning, architecture, design, development, procurement, deployment and maintenance. Applications, infrastructure, services, APIs, dependencies and third-party components are assessed according to their intended use, data sensitivity, exposure and risk. Material systems and external services are subject to security review before production use and whenever significant changes are introduced.
Uliaa’s secure-development practices include:
- threat modelling and security requirements for material features and system changes;
- documented architecture and design review for security-sensitive components;
- use of established frameworks, well-supported libraries and open standards;
- use of strong type systems and compile-time validation where appropriate to prevent classes of implementation errors;
- peer review and protected version control for source code and configuration;
- automated testing within continuous-integration and deployment pipelines;
- static analysis, dependency and software-composition scanning, and dynamic or runtime testing where appropriate;
- secure management of credentials, keys, secrets and build artefacts;
- review and remediation of vulnerabilities before release;
- controlled production deployment, change approval and rollback procedures; and
- periodic security testing, penetration testing and independent assessment.
Uliaa maintains software quality, resilience, maintainability and security as shared engineering responsibilities. Development records, test results, approvals and material changes are retained to support traceability, auditability and continuous improvement. Security defects identified after release are managed through Uliaa’s Vulnerability Management and Incident Response processes.
Disaster Recovery and Business Continuity
Uliaa maintains a disaster-recovery and business-continuity programme designed to preserve the confidentiality, integrity and availability of its systems and information during outages, infrastructure failures, cyber incidents, natural disasters and other disruptive events. The programme is risk-based and includes documented recovery procedures, defined responsibilities, service dependencies, communication paths and recovery priorities.
Key controls include:
- version control and protected change history for source code, infrastructure definitions, system configuration and deployment artefacts;
- repeatable infrastructure and application provisioning to support reliable restoration and recovery;
- regular backups of operational data, configuration, audit records and other critical information, protected against unauthorised access or alteration;
- geographically separated storage and, where appropriate, redundant hosting across independent facilities, availability zones and cloud infrastructure partners;
- use of multiple independent cloud infrastructure partners, with appropriate separation of hosting environments and recovery dependencies to reduce concentration risk and improve resilience during provider outages;
- resilient architectures, failover mechanisms and standby capacity appropriate to the service and its recovery requirements;
- periodic restoration tests to verify that backups are complete, usable and recoverable within agreed objectives;
- monitoring of backup jobs, replication, storage capacity and recovery dependencies;
- documented procedures for prioritising critical services, restoring operations and communicating with relevant stakeholders; and
- regular review and testing of the programme, including lessons learned from incidents, exercises and material changes to the platform.
Recovery arrangements are designed to support the retention periods and regulatory requirements described in Uliaa’s Data Retention policy. Recovery plans, test results and material changes are documented and retained as audit records.
Regulatory Compliance
Uliaa operates in the heavily regulated environment of financial systems, where the handling of personal information, financial data, investment content, trading activity and customer assets may be subject to detailed legal and regulatory requirements. These requirements vary across jurisdictions and may apply differently depending on the product, service, customer, transaction or market involved.
Uliaa maintains separate regulatory policies and control requirements for each jurisdiction in which it provides services to customers, reflecting the laws, supervisory expectations and market conditions applicable in that jurisdiction.
Uliaa is committed to designing and operating its platform in accordance with applicable laws, regulations, licences, industry obligations and contractual requirements. Regulatory considerations are incorporated into product design, risk assessments, data handling, access controls, recordkeeping, monitoring, incident response and customer communications. Where a feature or activity is subject to specific regulatory conditions, Uliaa applies appropriate controls, restrictions, reviews and approvals before making it available.
Uliaa works with legal, compliance and other appropriately qualified advisers to identify applicable obligations, maintain relevant policies and assess changes in the regulatory environment. Compliance requirements, assessments, approvals and material decisions are documented and retained as audit records. Where requirements are uncertain or differ between jurisdictions, Uliaa will restrict, adapt or defer the relevant activity until the applicable obligations have been assessed.
Our Security Commitment
Uliaa is committed to protecting the confidentiality, integrity and availability of its platform, systems, information and services. Security is treated as an ongoing organisational responsibility, supported by clear policies, accountable ownership, layered technical controls, secure engineering practices, continuous monitoring and regular independent review.
Our security programme evolves as Uliaa’s platform, technology, customer community, threat environment and regulatory obligations develop. We review and improve these controls over time, maintain jurisdiction-specific requirements where necessary, and use incidents, exercises, assessments and operational experience to strengthen our approach.
This policy describes Uliaa’s current security framework at a high level. It is supported by more detailed internal standards, procedures and technical controls, which may change as the platform and its operating environment evolve.