Platform

Enterprise Security

SOC 2 Type II Wealth Data Protection

SOC 2 Type II (Security), audited with zero exceptions. Encrypted in transit and at rest. Built for firms that take security seriously.

Security as Foundation

Controls You Can Show an Examiner

Your data lives in a database dedicated to your firm, with row-level access policies and column masking enforced in the data layer — not bolted on in the interface. Your team signs in through the identity provider you already run. And when your mandate calls for more — WORM retention, your own encryption keys, data held outside the US — we provision a dedicated environment to meet it.

Platform Foundation

Our Security Partnership

Amazon Web Services (AWS)

Multi-AZ redundancy with automated backup and recovery

AWS Shield DDoS protection and Web Application Firewall (WAF)

Private networking with VPC isolation

24/7 monitoring and threat detection

Amazon Web Services (AWS)

Multi-AZ redundancy with automated backup and recovery

AWS Shield DDoS protection and Web Application Firewall (WAF)

Private networking with VPC isolation

24/7 monitoring and threat detection

Snowflake Data Cloud

Encryption in transit and at rest, with a dedicated database per firm

Row-level access policies and column masking at table, column and row

Complete audit logging and data lineage tracking

Customer-managed keys and WORM retention in a dedicated environment

Snowflake Data Cloud

Encryption in transit and at rest, with a dedicated database per firm

Row-level access policies and column masking at table, column and row

Complete audit logging and data lineage tracking

Customer-managed keys and WORM retention in a dedicated environment

Regulatory Fit

When Your Mandate Demands More

Dedicated Environments

When configuration cannot meet your mandate, we provision a separate environment that does.

Dedicated Environments

When configuration cannot meet your mandate, we provision a separate environment that does.

Dedicated Environments

When configuration cannot meet your mandate, we provision a separate environment that does.

Recordkeeping and Retention

WORM retention with an irrevocable lock for SEC 17a-4 and FINRA 4511, in a dedicated environment.

Recordkeeping and Retention

WORM retention with an irrevocable lock for SEC 17a-4 and FINRA 4511, in a dedicated environment.

Recordkeeping and Retention

WORM retention with an irrevocable lock for SEC 17a-4 and FINRA 4511, in a dedicated environment.

Shared Responsibility

We secure and operate the platform. You keep control of identity, policy and who sees what.

Shared Responsibility

We secure and operate the platform. You keep control of identity, policy and who sees what.

Shared Responsibility

We secure and operate the platform. You keep control of identity, policy and who sees what.

Controls in Force

Core Security Controls

Data Zoning and Residency

A dedicated database per firm, isolated from every other tenant

Zoned by advisor, office and role, with PII masked by classification tag

Data residency options, including outside the US, in a dedicated environment

Data Zoning and Residency

A dedicated database per firm, isolated from every other tenant

Zoned by advisor, office and role, with PII masked by classification tag

Data residency options, including outside the US, in a dedicated environment

Compliance Ready

Complete audit trails for all actions

Privacy-by-design architecture

Regulatory alignment for financial services

Compliance Ready

Complete audit trails for all actions

Privacy-by-design architecture

Regulatory alignment for financial services

Data Zoning and Residency

A dedicated database per firm, isolated from every other tenant

Zoned by advisor, office and role, with PII masked by classification tag

Data residency options, including outside the US, in a dedicated environment

Compliance Ready

Complete audit trails for all actions

Privacy-by-design architecture

Regulatory alignment for financial services

Network Security

Private virtual cloud (VPC) isolation

Web Application Firewall (WAF) protection

Encrypted communication for all data transfer

Network Security

Private virtual cloud (VPC) isolation

Web Application Firewall (WAF) protection

Encrypted communication for all data transfer

Identity and Access

Single sign-on with Microsoft Entra ID, Google Workspace or Okta

Your identity provider stays the system of record for joiners and leavers

MFA and role-based least privilege enforced on every session

Identity and Access

Single sign-on with Microsoft Entra ID, Google Workspace or Okta

Your identity provider stays the system of record for joiners and leavers

MFA and role-based least privilege enforced on every session

Network Security

Private virtual cloud (VPC) isolation

Web Application Firewall (WAF) protection

Encrypted communication for all data transfer

Identity and Access

Single sign-on with Microsoft Entra ID, Google Workspace or Okta

Your identity provider stays the system of record for joiners and leavers

MFA and role-based least privilege enforced on every session

Our Commitment

Milemarker Security Commitment

Rigorous Internal Practices

Best-in-class security screening, training, and monitoring of our team and processes.

Rigorous Internal Practices

Connect Investment Decisions To Trade Execution

Automatic Allocation & Rebalancing

Real-Time Funding Alerts & Cash Management

Continuous Monitoring

Real-time threat detection and automated response systems protect your data around the clock.

Continuous Monitoring

Real-time threat detection and automated response systems protect your data around the clock.

Continuous Monitoring

Connect Investment Decisions To Trade Execution

Automatic Allocation & Rebalancing

Real-Time Funding Alerts & Cash Management

Regular Assessments

Independent penetration testing and vulnerability assessments ensure defenses stay current.

Regular Assessments

Independent penetration testing and vulnerability assessments ensure defenses stay current.

Regular Assessments

Comprehensive Performance Tracking Across All Investments

Risk Analytics & Attribution Reporting

Custom Benchmarking & Peer Comparisons

SOC 2 Type II Compliance

Annual audits and comprehensive compliance reporting for regulatory requirements.

SOC 2 Type II Compliance

Annual audits and comprehensive compliance reporting for regulatory requirements.

SOC 2 Type II Compliance

Comprehensive Performance Tracking Across All Investments

Risk Analytics & Attribution Reporting

Custom Benchmarking & Peer Comparisons

" Finally, someone is leveling up the data experience for advisors. What Milemarker is doing has been long overdue in the wealth management industry. "

Torie Happe

Holistiplan Head of Partnerships

" Finally, someone is leveling up the data experience for advisors. What Milemarker is doing has been long overdue in the wealth management industry. "

Torie Happe

Holistiplan Head of Partnerships

" Finally, someone is leveling up the data experience for advisors. What Milemarker is doing has been long overdue in the wealth management industry. "

Torie Happe

Holistiplan Head of Partnerships

Frequently asked questions.

Can’t find what you’re looking for? Reach out to our team at hello@milemarker.co

Which SOC 2 report do you hold, and can we review it?

Milemarker maintains a SOC 2 Type II report covering the Security trust services criterion, audited by an independent outside firm. The opinion is unqualified, with no exceptions noted.

The report is restricted-use, so we share it with clients and prospective clients under NDA rather than publishing it for download. Ask your Milemarker contact and we will arrange access for your reviewers.

How is our data separated from other firms?

Every firm's data sits in its own dedicated database, isolated from every other firm on the platform. Isolation is enforced in the data layer itself rather than in the application, so it holds regardless of how the data is reached.

Firms whose requirements call for a fully separate environment are provisioned one. We will walk your compliance team through the specifics under NDA.

Can our team sign in with our existing Microsoft, Google or Okta accounts?

Yes. Milemarker supports single sign-on against Microsoft Entra ID, Google Workspace and Okta, so your people sign in with the credentials they already have.

Your identity provider remains the system of record. Joiners and leavers are handled in the directory you already run, which means there is no separate Milemarker user list to maintain or to remember to deprovision when someone leaves. Multi-factor authentication and role-based least privilege are enforced on every session.

Can you meet our data residency requirements?

Yes. Where a firm has a residency obligation, we provision a dedicated environment in the jurisdiction that obligation requires.

Residency is a property of the environment rather than a setting, so it is scoped with you as part of implementation. Bring it up early and we will plan for it from the start.

Do you support SEC 17a-4, HIPAA and other regulated environments?

Yes. Milemarker offers SEC 17a-4 recordkeeping with WORM retention and an irrevocable retention lock, for broker-dealers who need it.

We also provision dedicated environments built to meet HIPAA and other regulatory regimes, so a firm with obligations beyond the standard deployment is not forced to choose between its platform and its mandate. Tell us the regime you are held to and we will scope the environment that satisfies it.

How do you control who inside our firm can see what?

Permissions are enforced in the data layer rather than in the interface, so a user sees the same permitted set no matter how they reach the data. Access is scoped by role — by advisor, office or team — and fields carrying personal information are masked from users who are not entitled to see them.

Your configuration is set up with you during implementation, and we will review it with your compliance team under NDA.

Is the platform penetration tested?

Yes. Milemarker is penetration tested, and remediations are retested to confirm they hold rather than closed on assertion.

Results are available to clients and prospective clients under NDA, alongside the SOC 2 Type II report.

Who owns the data, and what happens to it if we leave?

The data is yours. That is stated in our terms, not just our marketing.

You can export it in full, in standard formats, at any point during the relationship and on exit — not a report of it, the data itself. The platform and the engineering that normalizes and governs it remain Milemarker's; the data footprint is yours to take with you.

How quickly would we be told about a security incident?

Milemarker's terms commit us to notifying affected clients within 72 hours of confirming a breach involving their data.

Notification goes to the contacts your firm designates, and we coordinate directly with your compliance team throughout the response.

Frequently asked questions.

Can’t find what you’re looking for? Reach out to our team at hello@milemarker.co

Which SOC 2 report do you hold, and can we review it?

Milemarker maintains a SOC 2 Type II report covering the Security trust services criterion, audited by an independent outside firm. The opinion is unqualified, with no exceptions noted.

The report is restricted-use, so we share it with clients and prospective clients under NDA rather than publishing it for download. Ask your Milemarker contact and we will arrange access for your reviewers.

How is our data separated from other firms?

Every firm's data sits in its own dedicated database, isolated from every other firm on the platform. Isolation is enforced in the data layer itself rather than in the application, so it holds regardless of how the data is reached.

Firms whose requirements call for a fully separate environment are provisioned one. We will walk your compliance team through the specifics under NDA.

Can our team sign in with our existing Microsoft, Google or Okta accounts?

Yes. Milemarker supports single sign-on against Microsoft Entra ID, Google Workspace and Okta, so your people sign in with the credentials they already have.

Your identity provider remains the system of record. Joiners and leavers are handled in the directory you already run, which means there is no separate Milemarker user list to maintain or to remember to deprovision when someone leaves. Multi-factor authentication and role-based least privilege are enforced on every session.

Can you meet our data residency requirements?

Yes. Where a firm has a residency obligation, we provision a dedicated environment in the jurisdiction that obligation requires.

Residency is a property of the environment rather than a setting, so it is scoped with you as part of implementation. Bring it up early and we will plan for it from the start.

Do you support SEC 17a-4, HIPAA and other regulated environments?

Yes. Milemarker offers SEC 17a-4 recordkeeping with WORM retention and an irrevocable retention lock, for broker-dealers who need it.

We also provision dedicated environments built to meet HIPAA and other regulatory regimes, so a firm with obligations beyond the standard deployment is not forced to choose between its platform and its mandate. Tell us the regime you are held to and we will scope the environment that satisfies it.

How do you control who inside our firm can see what?

Permissions are enforced in the data layer rather than in the interface, so a user sees the same permitted set no matter how they reach the data. Access is scoped by role — by advisor, office or team — and fields carrying personal information are masked from users who are not entitled to see them.

Your configuration is set up with you during implementation, and we will review it with your compliance team under NDA.

Is the platform penetration tested?

Yes. Milemarker is penetration tested, and remediations are retested to confirm they hold rather than closed on assertion.

Results are available to clients and prospective clients under NDA, alongside the SOC 2 Type II report.

Who owns the data, and what happens to it if we leave?

The data is yours. That is stated in our terms, not just our marketing.

You can export it in full, in standard formats, at any point during the relationship and on exit — not a report of it, the data itself. The platform and the engineering that normalizes and governs it remain Milemarker's; the data footprint is yours to take with you.

How quickly would we be told about a security incident?

Milemarker's terms commit us to notifying affected clients within 72 hours of confirming a breach involving their data.

Notification goes to the contacts your firm designates, and we coordinate directly with your compliance team throughout the response.

Frequently asked questions.

Can’t find what you’re looking for? Reach out to our team at hello@milemarker.co

Which SOC 2 report do you hold, and can we review it?

Milemarker maintains a SOC 2 Type II report covering the Security trust services criterion, audited by an independent outside firm. The opinion is unqualified, with no exceptions noted.

The report is restricted-use, so we share it with clients and prospective clients under NDA rather than publishing it for download. Ask your Milemarker contact and we will arrange access for your reviewers.

How is our data separated from other firms?

Every firm's data sits in its own dedicated database, isolated from every other firm on the platform. Isolation is enforced in the data layer itself rather than in the application, so it holds regardless of how the data is reached.

Firms whose requirements call for a fully separate environment are provisioned one. We will walk your compliance team through the specifics under NDA.

Can our team sign in with our existing Microsoft, Google or Okta accounts?

Yes. Milemarker supports single sign-on against Microsoft Entra ID, Google Workspace and Okta, so your people sign in with the credentials they already have.

Your identity provider remains the system of record. Joiners and leavers are handled in the directory you already run, which means there is no separate Milemarker user list to maintain or to remember to deprovision when someone leaves. Multi-factor authentication and role-based least privilege are enforced on every session.

Can you meet our data residency requirements?

Yes. Where a firm has a residency obligation, we provision a dedicated environment in the jurisdiction that obligation requires.

Residency is a property of the environment rather than a setting, so it is scoped with you as part of implementation. Bring it up early and we will plan for it from the start.

Do you support SEC 17a-4, HIPAA and other regulated environments?

Yes. Milemarker offers SEC 17a-4 recordkeeping with WORM retention and an irrevocable retention lock, for broker-dealers who need it.

We also provision dedicated environments built to meet HIPAA and other regulatory regimes, so a firm with obligations beyond the standard deployment is not forced to choose between its platform and its mandate. Tell us the regime you are held to and we will scope the environment that satisfies it.

How do you control who inside our firm can see what?

Permissions are enforced in the data layer rather than in the interface, so a user sees the same permitted set no matter how they reach the data. Access is scoped by role — by advisor, office or team — and fields carrying personal information are masked from users who are not entitled to see them.

Your configuration is set up with you during implementation, and we will review it with your compliance team under NDA.

Is the platform penetration tested?

Yes. Milemarker is penetration tested, and remediations are retested to confirm they hold rather than closed on assertion.

Results are available to clients and prospective clients under NDA, alongside the SOC 2 Type II report.

Who owns the data, and what happens to it if we leave?

The data is yours. That is stated in our terms, not just our marketing.

You can export it in full, in standard formats, at any point during the relationship and on exit — not a report of it, the data itself. The platform and the engineering that normalizes and governs it remain Milemarker's; the data footprint is yours to take with you.

How quickly would we be told about a security incident?

Milemarker's terms commit us to notifying affected clients within 72 hours of confirming a breach involving their data.

Notification goes to the contacts your firm designates, and we coordinate directly with your compliance team throughout the response.

Let's Talk Security

Experience enterprise security that protects your business and satisfies your compliance requirements.

Direct access to our security experts for your questions.

Deep-dive into our security practices with your compliance team.

Let's Talk Security

Experience enterprise security that protects your business and satisfies your compliance requirements.

Direct access to our security experts for your questions.

Deep-dive into our security practices with your compliance team.

Let's Talk Security

Experience enterprise security that protects your business and satisfies your compliance requirements.

Direct access to our security experts for your questions.

Deep-dive into our security practices with your compliance team.

Ready to Connect Your Stack?

30-minute consultation on your data strategy and requirements.

Watch a walkthrough of the platform in action.

Ready to Connect Your Stack?

30-minute consultation on your data strategy and requirements.

Watch a walkthrough of the platform in action.

Ready to Connect Your Stack?

30-minute consultation on your data strategy and requirements.

Watch a walkthrough of the platform in action.