TW Market Data

Security facts

One page for a security reviewer. Every line is read from the same record the full security pages render, so this sheet cannot say something they do not — and each measured result carries the date it was measured, because a grade without its date is a claim about today that nobody re-earned.

Encryption in transit

Qualys SSL Labs
Grade A+ on all four endpoints. TLS 1.2 and 1.3 only — 1.0 and 1.1 are refused. No RC4, forward secrecy with every tested client, and no POODLE, Heartbleed, FREAK or Logjam exposure. Measured 2026-08-17.
HTTP Strict Transport Security
Enabled, max-age two years, includeSubDomains. NOT on the browser preload list, and the header does not yet carry the preload directive. Measured 2026-08-17.

Backups and who holds the data

Cloudflare R2
Off-site database backupsFull database dumps, which include account records. Object storage
Cloudflare
CDN, WAF and TLS terminationAll HTTP traffic to the site and API, including request IP addresses. Global edge
Recovery
Backups are taken daily, encrypted and off-site. Point-in-time recovery is on the roadmap below and is not in place, so the recovery granularity today is the daily backup, not an arbitrary moment.

What the data contains

Personal data
None. What is delivered is market, shareholding and regulatory disclosure data. The TDCC shareholding distribution is banded and aggregate — how many holders and how many shares fall in each band — not identities or accounts. So the data itself does not trigger data-subject obligations.
Non-public information
None. Sources are first-hand official disclosure — TWSE, TPEx, TAIFEX, TDCC, MOPS and open macroeconomic sources. We do not scrape third-party sites and do not use expert networks.
Account data
Separate from the market data, and it is the part that leaves our systems: full database dumps include account records, which is why the backup row above names what that provider can see.

Access controls

In use today
Single sign-on, Roles and least privilege (TWMD operators), Dashboard and credential governance, Human approval for CLI and agent access, Per-call audit records
Not built
Role-based access control over data requests, SCIM provisioning — listed because a reviewer needs the absences, not only the presences.

Certification status

We hold no third-party certification. This board is what we have, what is underway, and what has not been started — in that order, and the third column is the one worth reading first.

Done — publicly re-checkable

  • Qualys SSL Labs A+ on all four endpoints
  • HSTS enabled (not yet on the browser preload list)
  • Verifiable proof: public endpoints plus a standard-library verifier
  • No material non-public information, no personal data in the market data
  • SIG-Lite / CAIQ-Lite self-assessment published in full (a self-assessment, not a third-party certification)

In progress

  • GDPR and privacy documentation
  • Per-dataset attribution rollout

Roadmap — not started

  • Third-party penetration test
  • SOC 2
  • ISO 27001
  • Database encryption at rest
  • Point-in-time recovery

Check it yourself

The TLS grade can be re-run by anyone against our public hostnames. The proof mechanism is a set of keyless endpoints and a standard-library verifier that imports nothing of ours. The full self-assessment — including the answers that count against us — is published rather than sent on request.

Printed copies go stale. Every URL above resolves to the current position, and this sheet is generated from the same records those pages render.