Trust Center
Security posture, ten sections a reviewer can cite individually, every legal document in one place — and what we do not yet have.
Last updated 23 July 2026
1. Start here
One place to send a security reviewer, a procurement team or counsel. Each section below is a document in its own right, so it can be cited individually rather than as part of a page someone has to scroll.
If you only read one thing, read Authorization. It is the property that distinguishes this platform, and it is the one an examiner tests first: authentication establishes who is calling, but it does not establish whether that caller may reach this record, for this purpose, under the delegation in force right now.
Talk to us Standing up a trust company
2. Sections
| Section | What it covers |
|---|---|
| Security | The control model: what is enforced, where, and what evidence each control produces. |
| Authorization | How allow/deny is decided per data element, per purpose, per delegation — and revoked. |
| Compliance | The regulatory surface by account type, and where the institution’s duty begins. |
| Examination support | What we can put in front of your examiner, and what we cannot. |
| Data protection and PII handling | How a tax identifier is held outside the record, and who may read one. Design published; implementation in progress. |
| Privacy at A8 Core | How the binding Privacy Policy works in practice inside a deployment. |
| Data residency | Where data lives, what crosses a border, and why region is set before provisioning. |
| Resilience and continuity | Availability, backup, incident response, and the exit plan. |
| Secure development | How changes reach production and how they are traced back. |
| Supply chain | How third parties are selected, bounded, monitored — and how you assess the chain. |
| Vulnerability disclosure | How to report an issue, and the safe harbour for good-faith research. |
Two related pages sit outside the Trust Center because they are referenced by contract: the subprocessor register is Exhibit C to the DPA, and status reports current operational state.
3. Legal and contractual documents
| Document | Purpose |
|---|---|
| Platform Licence Agreement | Standard form licence, metered on data and usage, signable online |
| Data Processing Agreement | Processor terms, security, breach notice, transfers, deletion |
| Subprocessors | Exhibit C — Azure and Twilio as constants, rest per deployment |
| Acceptable Use Policy | Prohibited use, credential duties, scoped suspension |
| API Terms | Terms for API access, signable online |
| Mutual NDA | For evaluation conversations, signable online |
| Security policy | Control detail and coordinated-disclosure contact |
| Privacy Policy | The binding privacy notice for our own processing |
| Website terms · Cookies | Site use |
4. For a vendor-risk review
Email legal@a8core.com naming your institution and intended environment, and we will return the three completed DPA exhibits together — A (nature of processing), B (technical and organisational measures) and C (subprocessors with role and region). Those three are what a vendor-risk file normally needs; requesting them separately is how a review takes three weeks instead of three days.
Send your own questionnaire and control framework if you have them. We would rather map to your vocabulary than have you translate ours — a reviewer comparing two vocabularies finds differences that are not there.
5. What we do not yet have
Stating this plainly is more useful to a reviewer than a page of reassurance, and it is repeated in each section it affects.
- Institutional Trust Company is not chartered. It is a proposed trust entity seeking a South Dakota non-depository trust charter, is not accepting accounts, and no regulator has approved any application. See the de novo path.
- No published third-party audit report. Where a current report or completed questionnaire exists we offer it before asking you to run your own audit; where it does not, we say so.
- No paid bug-bounty programme — see vulnerability disclosure for what we do commit to.
- Early-stage evaluation records are captured in a system whose retention we will name on request; production execution moves to a dedicated document-execution provider.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice, an offer or solicitation of any security, or a guarantee against loss.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.