What we hold, and what we don't.
Fahali is read-only by design. It observes and notifies; your desk decides and executes. This page states plainly how data is handled, how the record is kept tamper-evident, and which certifications exist today.
The shortest version: no order routing, no path to capital, no custody of assets. The free read stores nothing. Records are append-only and every issued read carries a SHA-256 integrity hash.
Architecture
Read-only by design. Fahali has no order-routing capability and no path to capital. There is no code path by which it can place a trade, move funds, or take custody. This is an architectural property, not a policy setting — it cannot be enabled by a configuration change.
Broker connections are read-scoped. Where a desk connects a brokerage or exchange account for portfolio sync, credentials are stored encrypted with AES-256-GCM under a rotating key and used only for read operations.
Market data is public. Detection runs on public market data. Fahali does not claim privileged dark-pool prints, Level-2 order-book feeds, or on-chain settlement data — order-flow signals are labelled inferential proxies throughout the product.
Data handling
The free read stores nothing. A read computed on symbols typed into the landing page is evaluated live and discarded. Saving a book is what an account is for.
Transport and storage. TLS 1.3 in transit, AES-256 at rest. Access to production data is limited to the operators who run the service.
We do not sell personal data. Data is shared only with the infrastructure providers required to run the service — hosting, payment processing — under their respective agreements. Full detail is in the privacy policy.
Integrity of the record
The judged record is the product, so its integrity is the thing most worth protecting.
Pre-registration. Every predictive claim is written to the outcome ledger with its horizon before the outcome exists. A claim cannot be added, reworded, or reordered after the market has moved.
Append-only. Outcomes are resolved against realized price and retained. Wrong calls stay in the same ledger as correct ones. The record is not back-filled.
Tamper-evident, not tamper-proof. Each issued read carries a SHA-256 integrity hash and a provenance root, so a modified receipt can be detected. We use the precise word: this makes alteration detectable, which is not the same as making it impossible. Key-signed attestation is on the roadmap.
Certifications
Stated plainly, because a procurement questionnaire will ask and a straight answer now is cheaper than a discovery later.
| Framework | Status |
|---|---|
| SOC 2 Type II | Not certified — planned |
| ISO 27001 | Not certified — planned |
| MiFID II record-keeping format | Not certified — planned |
| SEC Rule 17a-4 export format | Not certified — planned |
| GDPR data-subject rights | Honoured — access, correction, deletion, export |
Records are append-only and timestamped in a form built for audit, which is a precondition for those frameworks rather than a substitute for them. If a certification is a procurement gate for you, tell us which one and when you need it — that information shapes the order we pursue them in.
Reporting a vulnerability
Responsible disclosure
If you find a security issue, write to us before disclosing it publicly. We will confirm receipt, tell you what we found, and credit you if you want the credit.
Report an issue →Data processing agreement
DPA and security questionnaires
We sign DPAs and complete security questionnaires. Send yours and we will return it completed rather than ask you to accept a summary.
Request a DPA →