Security

Handling desk data the way a desk expects.

Synthetix reads order parameters from institutional conversations. That places us inside a regulated workflow, and the platform is built accordingly.

Last updated August 2026

Validated before it leaves

Dual-layer architecture

Every extracted parameter is checked by a deterministic rules layer before any outbound request — underlying identifiers, barrier and strike relationships, currency and tenor bounds, and logical anomalies.

Supervised where it matters

Human in the loop

When extraction confidence falls below defined thresholds, the request is routed to a human for confirmation rather than being sent automatically.

Nothing to install

Zero issuer integration

Issuers receive requests in the formats their auto-pricers already accept. No credentials, endpoints or infrastructure are required on the sell side.

Access to your channels

Synthetix connects to the communication channels a desk authorises, and only those. Access is scoped to the conversations in the agreed pilot perimeter, and is revocable by the desk at any time without our involvement.

We do not require credentials for issuer portals, order management systems or custody platforms, because the platform does not connect to them.

What we hold

  • The originating request as it appeared in the channel
  • The canonical parameters extracted from it
  • The outbound request sent to each issuer, and their replies
  • The ranked comparison and which quote was selected

This record exists to support supervision and best-execution review. It is time-stamped and tamper-evident, and it is the same record described on our compliance page.

Infrastructure

The platform runs on cloud infrastructure with encryption in transit and at rest, environment isolation between pilot desks, and least-privilege access for the small number of engineers who operate it. Administrative actions are logged.

Model behaviour

Large language models are probabilistic, and a single wrong digit in a strike, barrier or notional is not an acceptable failure mode. That is why extraction is never the last step before an outbound request: the deterministic validation layer sits between the model and the issuer, and low-confidence extractions stop for human confirmation.

Desk conversations are not used to train third-party foundation models.

Certification status

Synthetix is built to SOC 2 Type II control standards. We have not completed a SOC 2 Type II examination, and we do not describe ourselves as certified. When an examination is completed we will say so here, with the report available under NDA.

Annual budget is reserved for third-party security audits and vulnerability scanning, and we expect to meet the vendor risk-assessment criteria institutional desks apply.

Reporting a vulnerability

If you believe you have found a security issue, email hello@synthetix.systems. We will acknowledge your report and keep you updated while we investigate. Please give us a reasonable opportunity to remediate before public disclosure.