Security
Written for the person who has to sign off on this, not for the person who wants to buy it. If something below is not good enough for your firm, better you find out now.
What Trueband will never do
- Place a trade, or connect to anything that can.
- Send an email. Every client message is created as an unsent draft in an advisor's own mailbox.
- Write anything back to Orion or Eclipse. Every call we make to either is a read.
- Move money, change an account, or alter a model.
What it reads
From Orion core: your client and account records, holdings, and account performance. From Eclipse: portfolios, their assigned models, and each model's target weights and tolerance bands. That is the whole list. Access uses the credentials your firm supplies, so what we can see is bounded by the role you give that user, and you can revoke it in Orion without talking to us.
What it stores
A computed drift record per household: the household name, its account count and total value, the per-asset-class current and target weights, the resulting deviation, and the status. Where an advisor has recorded one, the video and its still frame. Where an advisor has edited an email, that text.
We do not store account numbers, tax identifiers, dates of birth, or transaction history, because the product has no use for them.
Who can see it
The application sits behind Cloudflare Access with your own identity provider in front of it, and the application checks the signed identity again on every request against an allowlist your firm controls. A request without a valid, allowlisted identity is refused outright rather than redirected or partially rendered.
Client videos are the one deliberate exception. A client has no login with us, so their video page is reachable by an unguessable per video link and nothing else. It shows the video and nothing about the portfolio.
Where it runs
Entirely on Cloudflare's network. Compute runs in Workers, drift records live in Workers KV, and video objects live in R2. There is no server of ours for someone to log into, because there is no server.
What we have not done yet
Trueband is early, and a trust page that hides that is worthless. We are not SOC 2 certified. We do not yet hold an independent penetration test report. Per firm credential encryption under a customer managed key, retention controls, archive export to a compliance vendor, and an immutable audit log are designed but not shipped. If your firm requires any of those before signing, tell us and we will tell you honestly where it sits.
Reporting something
If you find a vulnerability, write to a@ashkaan.me. We will confirm receipt within one business day and will not pursue anyone who reports in good faith.
See it on fictional households first.
No signup, no call, nothing sends. It runs on fictional households and the buttons in it do not reach a mailbox. Questions it does not answer go to a@ashkaan.me.