OpenSecondaries

A private venue for institutional investors

Security posture

How member material is protected.

Members give the venue two sensitive things: their documents and their identity. The posture below protects both. Questions about any of it are welcome at [email protected].

Invitation only, named users only

There is no signup page. Each institution is approved individually, and each user is a named person invited by the venue's administrators. Sign-in uses single-use links sent to the approved institutional email address.

Agreements before upload

Confidentiality and participation agreements are executed before any document changes hands, and every version of every agreement a member accepts is recorded.

Encryption in transit and at rest

All traffic is encrypted in transit. Member documents are encrypted before they reach storage and stay encrypted at rest.

Every access is logged

Each access to a member document or record is written to an append-only audit log with the identity of the person or process that made it.

Institutions are isolated

Each institution's records are segregated at the database layer. One member's material is structurally invisible to another member's session.

Identity and listings live apart

Member identity and listing information are held in separate records by design. The records buyers see carry no member identity at all.

Documents are never redistributed

Buyers see bucketed abstractions, never member documents. A document is shared only when its owner approves a specific verified counterparty, under agreements already in place.

Administrative access is zero-trust

Internal consoles sit behind identity-verified zero-trust access, and administrative actions land in the same append-only audit log.

No trackers, anywhere

The member application carries no third-party analytics. This public site is static: no cookies, no scripts, no outside services of any kind.

Reporting a concern

If you believe you have found a security problem in anything we operate, write to [email protected]. Reports are read by the people who can act on them.