Platform
Platform
Enterprise Security
SOC 2 Type II Wealth Data Protection
SOC 2 Type II (Security), audited with zero exceptions. Encrypted in transit and at rest. Built for firms that take security seriously.


Security as Foundation
Controls You Can Show an Examiner
Your data lives in a database dedicated to your firm, with row-level access policies and column masking enforced in the data layer — not bolted on in the interface. Your team signs in through the identity provider you already run. And when your mandate calls for more — WORM retention, your own encryption keys, data held outside the US — we provision a dedicated environment to meet it.
Platform Foundation
Our Security Partnership
Amazon Web Services (AWS)
Multi-AZ redundancy with automated backup and recovery
AWS Shield DDoS protection and Web Application Firewall (WAF)
Private networking with VPC isolation
24/7 monitoring and threat detection

Amazon Web Services (AWS)
Multi-AZ redundancy with automated backup and recovery
AWS Shield DDoS protection and Web Application Firewall (WAF)
Private networking with VPC isolation
24/7 monitoring and threat detection

Snowflake Data Cloud
Encryption in transit and at rest, with a dedicated database per firm
Row-level access policies and column masking at table, column and row
Complete audit logging and data lineage tracking
Customer-managed keys and WORM retention in a dedicated environment

Snowflake Data Cloud
Encryption in transit and at rest, with a dedicated database per firm
Row-level access policies and column masking at table, column and row
Complete audit logging and data lineage tracking
Customer-managed keys and WORM retention in a dedicated environment

Regulatory Fit
When Your Mandate Demands More
Dedicated Environments
When configuration cannot meet your mandate, we provision a separate environment that does.
Dedicated Environments
When configuration cannot meet your mandate, we provision a separate environment that does.
Dedicated Environments
When configuration cannot meet your mandate, we provision a separate environment that does.
Recordkeeping and Retention
WORM retention with an irrevocable lock for SEC 17a-4 and FINRA 4511, in a dedicated environment.
Recordkeeping and Retention
WORM retention with an irrevocable lock for SEC 17a-4 and FINRA 4511, in a dedicated environment.
Recordkeeping and Retention
WORM retention with an irrevocable lock for SEC 17a-4 and FINRA 4511, in a dedicated environment.
Shared Responsibility
We secure and operate the platform. You keep control of identity, policy and who sees what.
Shared Responsibility
We secure and operate the platform. You keep control of identity, policy and who sees what.
Shared Responsibility
We secure and operate the platform. You keep control of identity, policy and who sees what.
Controls in Force
Core Security Controls
Data Zoning and Residency
A dedicated database per firm, isolated from every other tenant
Zoned by advisor, office and role, with PII masked by classification tag
Data residency options, including outside the US, in a dedicated environment

Data Zoning and Residency
A dedicated database per firm, isolated from every other tenant
Zoned by advisor, office and role, with PII masked by classification tag
Data residency options, including outside the US, in a dedicated environment
Compliance Ready
Complete audit trails for all actions
Privacy-by-design architecture
Regulatory alignment for financial services
Compliance Ready
Complete audit trails for all actions
Privacy-by-design architecture
Regulatory alignment for financial services
Data Zoning and Residency
A dedicated database per firm, isolated from every other tenant
Zoned by advisor, office and role, with PII masked by classification tag
Data residency options, including outside the US, in a dedicated environment
Compliance Ready
Complete audit trails for all actions
Privacy-by-design architecture
Regulatory alignment for financial services
Network Security
Private virtual cloud (VPC) isolation
Web Application Firewall (WAF) protection
Encrypted communication for all data transfer
Network Security
Private virtual cloud (VPC) isolation
Web Application Firewall (WAF) protection
Encrypted communication for all data transfer
Identity and Access
Single sign-on with Microsoft Entra ID, Google Workspace or Okta
Your identity provider stays the system of record for joiners and leavers
MFA and role-based least privilege enforced on every session

Identity and Access
Single sign-on with Microsoft Entra ID, Google Workspace or Okta
Your identity provider stays the system of record for joiners and leavers
MFA and role-based least privilege enforced on every session
Network Security
Private virtual cloud (VPC) isolation
Web Application Firewall (WAF) protection
Encrypted communication for all data transfer
Identity and Access
Single sign-on with Microsoft Entra ID, Google Workspace or Okta
Your identity provider stays the system of record for joiners and leavers
MFA and role-based least privilege enforced on every session
Our Commitment
Milemarker Security Commitment
Rigorous Internal Practices
Best-in-class security screening, training, and monitoring of our team and processes.
Rigorous Internal Practices
Connect Investment Decisions To Trade Execution
Automatic Allocation & Rebalancing
Real-Time Funding Alerts & Cash Management
Continuous Monitoring
Real-time threat detection and automated response systems protect your data around the clock.
Continuous Monitoring
Real-time threat detection and automated response systems protect your data around the clock.
Continuous Monitoring
Connect Investment Decisions To Trade Execution
Automatic Allocation & Rebalancing
Real-Time Funding Alerts & Cash Management
Regular Assessments
Independent penetration testing and vulnerability assessments ensure defenses stay current.
Regular Assessments
Independent penetration testing and vulnerability assessments ensure defenses stay current.
Regular Assessments
Comprehensive Performance Tracking Across All Investments
Risk Analytics & Attribution Reporting
Custom Benchmarking & Peer Comparisons
SOC 2 Type II Compliance
Annual audits and comprehensive compliance reporting for regulatory requirements.
SOC 2 Type II Compliance
Annual audits and comprehensive compliance reporting for regulatory requirements.
SOC 2 Type II Compliance
Comprehensive Performance Tracking Across All Investments
Risk Analytics & Attribution Reporting
Custom Benchmarking & Peer Comparisons
" Finally, someone is leveling up the data experience for advisors. What Milemarker is doing has been long overdue in the wealth management industry. "

Torie Happe
Holistiplan Head of Partnerships
" Finally, someone is leveling up the data experience for advisors. What Milemarker is doing has been long overdue in the wealth management industry. "

Torie Happe
Holistiplan Head of Partnerships
" Finally, someone is leveling up the data experience for advisors. What Milemarker is doing has been long overdue in the wealth management industry. "

Torie Happe
Holistiplan Head of Partnerships
Frequently asked questions.
Can’t find what you’re looking for? Reach out to our team at hello@milemarker.co
Which SOC 2 report do you hold, and can we review it?
Milemarker maintains a SOC 2 Type II report covering the Security trust services criterion, audited by an independent outside firm. The opinion is unqualified, with no exceptions noted.
The report is restricted-use, so we share it with clients and prospective clients under NDA rather than publishing it for download. Ask your Milemarker contact and we will arrange access for your reviewers.
How is our data separated from other firms?
Every firm's data sits in its own dedicated database, isolated from every other firm on the platform. Isolation is enforced in the data layer itself rather than in the application, so it holds regardless of how the data is reached.
Firms whose requirements call for a fully separate environment are provisioned one. We will walk your compliance team through the specifics under NDA.
Can our team sign in with our existing Microsoft, Google or Okta accounts?
Yes. Milemarker supports single sign-on against Microsoft Entra ID, Google Workspace and Okta, so your people sign in with the credentials they already have.
Your identity provider remains the system of record. Joiners and leavers are handled in the directory you already run, which means there is no separate Milemarker user list to maintain or to remember to deprovision when someone leaves. Multi-factor authentication and role-based least privilege are enforced on every session.
Can you meet our data residency requirements?
Yes. Where a firm has a residency obligation, we provision a dedicated environment in the jurisdiction that obligation requires.
Residency is a property of the environment rather than a setting, so it is scoped with you as part of implementation. Bring it up early and we will plan for it from the start.
Do you support SEC 17a-4, HIPAA and other regulated environments?
Yes. Milemarker offers SEC 17a-4 recordkeeping with WORM retention and an irrevocable retention lock, for broker-dealers who need it.
We also provision dedicated environments built to meet HIPAA and other regulatory regimes, so a firm with obligations beyond the standard deployment is not forced to choose between its platform and its mandate. Tell us the regime you are held to and we will scope the environment that satisfies it.
How do you control who inside our firm can see what?
Permissions are enforced in the data layer rather than in the interface, so a user sees the same permitted set no matter how they reach the data. Access is scoped by role — by advisor, office or team — and fields carrying personal information are masked from users who are not entitled to see them.
Your configuration is set up with you during implementation, and we will review it with your compliance team under NDA.
Is the platform penetration tested?
Yes. Milemarker is penetration tested, and remediations are retested to confirm they hold rather than closed on assertion.
Results are available to clients and prospective clients under NDA, alongside the SOC 2 Type II report.
Who owns the data, and what happens to it if we leave?
The data is yours. That is stated in our terms, not just our marketing.
You can export it in full, in standard formats, at any point during the relationship and on exit — not a report of it, the data itself. The platform and the engineering that normalizes and governs it remain Milemarker's; the data footprint is yours to take with you.
How quickly would we be told about a security incident?
Milemarker's terms commit us to notifying affected clients within 72 hours of confirming a breach involving their data.
Notification goes to the contacts your firm designates, and we coordinate directly with your compliance team throughout the response.
Frequently asked questions.
Can’t find what you’re looking for? Reach out to our team at hello@milemarker.co
Which SOC 2 report do you hold, and can we review it?
Milemarker maintains a SOC 2 Type II report covering the Security trust services criterion, audited by an independent outside firm. The opinion is unqualified, with no exceptions noted.
The report is restricted-use, so we share it with clients and prospective clients under NDA rather than publishing it for download. Ask your Milemarker contact and we will arrange access for your reviewers.
How is our data separated from other firms?
Every firm's data sits in its own dedicated database, isolated from every other firm on the platform. Isolation is enforced in the data layer itself rather than in the application, so it holds regardless of how the data is reached.
Firms whose requirements call for a fully separate environment are provisioned one. We will walk your compliance team through the specifics under NDA.
Can our team sign in with our existing Microsoft, Google or Okta accounts?
Yes. Milemarker supports single sign-on against Microsoft Entra ID, Google Workspace and Okta, so your people sign in with the credentials they already have.
Your identity provider remains the system of record. Joiners and leavers are handled in the directory you already run, which means there is no separate Milemarker user list to maintain or to remember to deprovision when someone leaves. Multi-factor authentication and role-based least privilege are enforced on every session.
Can you meet our data residency requirements?
Yes. Where a firm has a residency obligation, we provision a dedicated environment in the jurisdiction that obligation requires.
Residency is a property of the environment rather than a setting, so it is scoped with you as part of implementation. Bring it up early and we will plan for it from the start.
Do you support SEC 17a-4, HIPAA and other regulated environments?
Yes. Milemarker offers SEC 17a-4 recordkeeping with WORM retention and an irrevocable retention lock, for broker-dealers who need it.
We also provision dedicated environments built to meet HIPAA and other regulatory regimes, so a firm with obligations beyond the standard deployment is not forced to choose between its platform and its mandate. Tell us the regime you are held to and we will scope the environment that satisfies it.
How do you control who inside our firm can see what?
Permissions are enforced in the data layer rather than in the interface, so a user sees the same permitted set no matter how they reach the data. Access is scoped by role — by advisor, office or team — and fields carrying personal information are masked from users who are not entitled to see them.
Your configuration is set up with you during implementation, and we will review it with your compliance team under NDA.
Is the platform penetration tested?
Yes. Milemarker is penetration tested, and remediations are retested to confirm they hold rather than closed on assertion.
Results are available to clients and prospective clients under NDA, alongside the SOC 2 Type II report.
Who owns the data, and what happens to it if we leave?
The data is yours. That is stated in our terms, not just our marketing.
You can export it in full, in standard formats, at any point during the relationship and on exit — not a report of it, the data itself. The platform and the engineering that normalizes and governs it remain Milemarker's; the data footprint is yours to take with you.
How quickly would we be told about a security incident?
Milemarker's terms commit us to notifying affected clients within 72 hours of confirming a breach involving their data.
Notification goes to the contacts your firm designates, and we coordinate directly with your compliance team throughout the response.
Frequently asked questions.
Can’t find what you’re looking for? Reach out to our team at hello@milemarker.co
Which SOC 2 report do you hold, and can we review it?
Milemarker maintains a SOC 2 Type II report covering the Security trust services criterion, audited by an independent outside firm. The opinion is unqualified, with no exceptions noted.
The report is restricted-use, so we share it with clients and prospective clients under NDA rather than publishing it for download. Ask your Milemarker contact and we will arrange access for your reviewers.
How is our data separated from other firms?
Every firm's data sits in its own dedicated database, isolated from every other firm on the platform. Isolation is enforced in the data layer itself rather than in the application, so it holds regardless of how the data is reached.
Firms whose requirements call for a fully separate environment are provisioned one. We will walk your compliance team through the specifics under NDA.
Can our team sign in with our existing Microsoft, Google or Okta accounts?
Yes. Milemarker supports single sign-on against Microsoft Entra ID, Google Workspace and Okta, so your people sign in with the credentials they already have.
Your identity provider remains the system of record. Joiners and leavers are handled in the directory you already run, which means there is no separate Milemarker user list to maintain or to remember to deprovision when someone leaves. Multi-factor authentication and role-based least privilege are enforced on every session.
Can you meet our data residency requirements?
Yes. Where a firm has a residency obligation, we provision a dedicated environment in the jurisdiction that obligation requires.
Residency is a property of the environment rather than a setting, so it is scoped with you as part of implementation. Bring it up early and we will plan for it from the start.
Do you support SEC 17a-4, HIPAA and other regulated environments?
Yes. Milemarker offers SEC 17a-4 recordkeeping with WORM retention and an irrevocable retention lock, for broker-dealers who need it.
We also provision dedicated environments built to meet HIPAA and other regulatory regimes, so a firm with obligations beyond the standard deployment is not forced to choose between its platform and its mandate. Tell us the regime you are held to and we will scope the environment that satisfies it.
How do you control who inside our firm can see what?
Permissions are enforced in the data layer rather than in the interface, so a user sees the same permitted set no matter how they reach the data. Access is scoped by role — by advisor, office or team — and fields carrying personal information are masked from users who are not entitled to see them.
Your configuration is set up with you during implementation, and we will review it with your compliance team under NDA.
Is the platform penetration tested?
Yes. Milemarker is penetration tested, and remediations are retested to confirm they hold rather than closed on assertion.
Results are available to clients and prospective clients under NDA, alongside the SOC 2 Type II report.
Who owns the data, and what happens to it if we leave?
The data is yours. That is stated in our terms, not just our marketing.
You can export it in full, in standard formats, at any point during the relationship and on exit — not a report of it, the data itself. The platform and the engineering that normalizes and governs it remain Milemarker's; the data footprint is yours to take with you.
How quickly would we be told about a security incident?
Milemarker's terms commit us to notifying affected clients within 72 hours of confirming a breach involving their data.
Notification goes to the contacts your firm designates, and we coordinate directly with your compliance team throughout the response.
Let's Talk Security
Experience enterprise security that protects your business and satisfies your compliance requirements.
Direct access to our security experts for your questions.
Deep-dive into our security practices with your compliance team.
Let's Talk Security
Experience enterprise security that protects your business and satisfies your compliance requirements.
Direct access to our security experts for your questions.
Deep-dive into our security practices with your compliance team.
Let's Talk Security
Experience enterprise security that protects your business and satisfies your compliance requirements.
Direct access to our security experts for your questions.
Deep-dive into our security practices with your compliance team.
Ready to Connect Your Stack?
30-minute consultation on your data strategy and requirements.
Watch a walkthrough of the platform in action.

Ready to Connect Your Stack?
30-minute consultation on your data strategy and requirements.
Watch a walkthrough of the platform in action.

Ready to Connect Your Stack?
30-minute consultation on your data strategy and requirements.
Watch a walkthrough of the platform in action.
