Under construction This website is currently being rebuilt. Content is provisional — messages are welcome at any time. kontakt@jkhd.de

// Security & confidentiality

What you give us stays yours.

Having a trading system built means handing something over: an idea, a set of data, sometimes market access. This page says how we handle it — and names openly, at the end, what we cannot show you.

// Principles

Four rules that are not up for negotiation.

Separated, not shared

Every mandate has its own storage, its own version control and its own credentials. Nothing from one project sits where another is being worked on — not even alongside our own systems.

No copy, no derivative

What we build for you belongs to you entirely. No resale, no second edition, no use of your parameters or results as a starting point for another house's work.

As little as possible

We ask only for what building requires — as a rule market data and a technical specification. No personal data, no client data of yours, no portfolio holdings, no authority over accounts.

Everything traceable

Every change is versioned, every access to a running system logged. Who changed what and when is still answerable months later — for you as much as for us.

// In detail

Six places where it becomes concrete.

Security is not decided by a statement but by small things: where a key is kept, who can revoke it, what happens to it after the last working day.

01

People and access

We are a small house — you know by name who works on your project.

  • The individuals involved are named to you in advance
  • No subcontractors without your written consent
  • Access only for as long as the task requires it
  • Confidentiality applies indefinitely, including after the project
02

Keys and credentials

Credentials for the data feed and the broker are the most sensitive thing in the whole project.

  • Keys never appear in source code and never in a log
  • Never handed over by e-mail or chat
  • Credentials are issued in your name and revocable at any time
  • Separate credentials for testing and operation
  • Where possible: rights limited to what is needed
03

Your data

What you give us stays limited to what building actually requires.

  • Market data and a specification instead of client data
  • Transfer encrypted, over an agreed channel
  • If personal data does become necessary: processing agreement under Art. 28 GDPR
  • No disclosure to third parties, no evaluation for our own purposes
04

Operation

Where a system runs is your institution's decision, not ours.

  • If it runs at your site, we have no access
  • Remote access only time-limited, announced and logged
  • Changes to a running system are approved beforehand
  • Every state is versioned and can be rolled back
05

End of project

The most important part: what happens once we are finished.

  • Complete handover: source code, documents, logs
  • Deletion of our working copies after the agreed period
  • You receive confirmation of the deletion in writing
  • Credentials are revoked by you, and we confirm it
  • Named as a reference only if you expressly release it
06

This website

What applies to commissions applies to the page you are on right now.

  • No cookies, no trackers, no analytics services
  • Fonts are hosted locally, no third-party content
  • No form sends to a server — nor the partner access while it is being set up
  • Details in the privacy policy

// Sequence

From the first conversation to deletion.

Confidentiality is not a declaration at the start but a chain of steps. Here it is.

01

Confidentiality before content

Before you tell us any detail, we sign a non-disclosure agreement — yours or ours, your choice. For a first exploratory conversation we need no confidential information at all.

02

An agreed channel for documents

We settle what documents are exchanged over and who may see them. Not an attachment on some e-mail, not a folder with a service nobody has named.

03

A separate working environment

Your project gets its own environment with its own version control. It is separate from our own systems and from every other mandate.

04

Testing and operation

Testing runs first without market access, then with separate test credentials. Only at trial operation do real credentials come into play — in your name, with the rights needed for it and no others.

05

Handover

You get everything: source code, test report, logs, operating manual. From that point your house can run the system without us — that is the standard we measure the handover against.

06

Deletion, confirmed

After the agreed period we delete our working copies and confirm it to you in writing. What remains with us afterwards is the fact that we worked for you — and even that we mention only if you release it.

If something happens: should an incident affect your documents, credentials or data, we report it without delay and in writing to the contact you name — with what is known at that point, even if the picture is still incomplete. Fixed reporting deadlines and escalation paths are set down in the contract, so that they do not have to be negotiated in an emergency.

// Honestly

What we cannot show you.

This list is here so that you do not have to discover it in the questionnaire.

No certification

We are not certified to ISO 27001 and hold no comparable seal. What we commit to is in the contract — not in a certificate.

No external audit

Our procedures have not so far been examined by a third party. If your policy requires that, we will tell you in advance whether and how we can provide it.

No round-the-clock security team

We monitor the systems we operate continuously, but we do not maintain a security department of our own. Anyone who needs that structure should look for it at a larger provider.

We decline when it does not fit

If your requirements demand something we cannot honestly meet, we turn the commission down. That is cheaper for both sides than a tick in a box that does not hold up under examination.

Do you have a questionnaire?

Send it to us. We will fill it in and state honestly where we have to put a no.

Get in touch How we test