Security & compliance
Client financial data deserves more than a checkbox.
LogiqWealth is built for SEC/FINRA-regulated firms. Every control below exists to support your obligations, not get in the way of them.
Encryption everywhere
Client PII, account data and documents are classified Restricted and handled accordingly.
- TLS 1.2+ on every endpoint; no plaintext HTTP
- Encryption at rest for the database and document storage
- Credentials and signing keys kept in a secrets manager, never in config
Strict tenant isolation
Each firm's data is isolated by design, not by policy.
- Row-level isolation on every firm-scoped record
- Defense in depth at the application and gateway layers
- No cross-tenant access path exists
Access you can reason about
Role-based access mapped to how advisory firms actually work.
- MFA required for every user, staff and client
- Roles for principals, associates, covering advisors, compliance and IT
- Advisors see only the clients assigned to them
An audit log nobody can edit
Every login, document change, correction, report and approval is recorded.
- Append-only, enforced in the application, by database triggers and in the grants
- Compliance officers annotate entries; annotations are immutable too
- Export as CSV or PDF for examinations
AI with guardrails
AI works only on data the application has already scoped to the right client.
- No AI feature can query the database directly
- Every extracted field carries a confidence score; low ones go to a human
- The client portal chat never gives investment or tax advice
Resilient operations
Encrypted, automated backups with restore procedures that are actually drilled.
- Centralized logging and uptime monitoring
- Anomaly detection for login spikes and unusual access
- Least-privilege, read-only scopes for connectors; signed webhooks
Compliance support
Tooling for your compliance program.
LogiqWealth is a data processor for your firm, not a registered investment advisor. Your compliance officer stays in charge; we make the evidence easy to produce.
Controls are aligned with SOC 2. Formal SOC 2 attestation is on our compliance roadmap.
Immutable audit trail
Supports SEC Rule 204-2 recordkeeping
Suitability and fiduciary templates
Fiduciary duty documentation
Filing deadline tracker
Fewer missed regulatory deadlines
Exportable compliance reports
Faster audit and exam preparation
E-signature with stored consent
KYC and suitability documentation trail
7-year retention floor
Regulated records cannot be purged early
Reliability & support
Uptime and response commitments by plan.
Uptime excludes scheduled maintenance, which we announce at least 48 hours ahead.
| Plan | Critical issue response | High priority response | Monthly uptime |
|---|---|---|---|
| Starter | 8 business hours | 1 business day | 99.5% |
| Growth | 4 business hours | 1 business day | 99.5% |
| Scale | 1 hour, 24/7 | 2 hours, 24/7 | 99.9% |
Incident response
A defined path from detection to containment, firm notification, remediation and post-incident review.
7-year retention
Regulated records are kept at least 7 years while you're a customer, and handed back in a full export if you leave.
Tested backups
Encrypted automated backups with restore procedures we drill, not assume.
Have a security questionnaire?
Our team will walk your compliance officer through the controls and answer your due-diligence questions.