Your firm’s data stays your firm’s.
OnTrade keeps each firm’s data, memory, and agent activity isolated. Client-identifiable information is used exclusively to provide services to your firm and is excluded from model training.
Customer-specific access controls separate your firm’s data and memory from every other OnTrade customer, and each agent runs inside its own network boundary.
Your identifiable client data is used to provide services to your firm. Customer prompts and outputs are excluded from model training.
Approval workflows keep important decisions with your professionals.
How OnTrade protects and uses your data
The controls behind our commitments to isolation, responsible AI use, and professional oversight.
Customer-specific access controls separate each firm’s data and platform memory, and each agent runs inside its own network boundary. Role-based permissions determine who within your organization can access specific information and capabilities.
The platform’s memory is per firm. What it retains to personalize your experience is used only to serve you — and your identifiable client data is never used to generate outputs for any other customer.
OnTrade specifies the approved provider and model used for each workflow. Model providers operate under commercial terms that exclude customer prompts and outputs from model training.
Configured approval workflows keep your professionals in control. Material agent actions, analyses, approvals, and outputs are logged to support review and oversight. OnTrade’s quantitative calculations use deterministic tools where reproducibility is required.
Security Controls.
Verified in our SOC 2 Type II audit — completed with no exceptions noted.
AES-256 encryption at rest
TLS 1.2 or higher in transit
Role-based access and least-privilege permissions
MFA for production and privileged access
Centralized security logging and detection
Quarterly vulnerability scanning
Annual independent penetration testing
Continuous control monitoring
Daily encrypted backups
Replication across availability zones
Documented incident-response procedures
Business-continuity and disaster-recovery testing annually
Formal data-classification and retention policies
Defined deletion procedures
Regular access reviews
Current subprocessor inventory
Vendor Review Essentials.
- Where is our data hosted?
On AWS in US regions. Additional details about infrastructure and data processing are available in the Trust Center.
- Is our data used to train AI models?
Customer prompts, outputs, and identifiable client information are excluded from model training under OnTrade’s agreements with its model providers.
- Is information shared across firms?
Each firm’s data and memory are isolated. Identifiable client information is used exclusively to provide services to that firm.
- How can we retrieve or delete our data?
OnTrade supports the return and deletion of customer data through a documented process. Deletion requests are completed within 30 days, subject to applicable legal and backup-retention requirements.
- Who are OnTrade’s subprocessors?
OnTrade maintains a current subprocessor list, including each provider’s purpose and processing location, and makes it available on written request.
- What happens during a security incident?
OnTrade follows a documented incident-response plan and provides notifications in accordance with contractual and legal requirements. Business-continuity and disaster-recovery plans are tested annually.