TW Market Data
Security facts
One page for a security reviewer. Every line is read from the same record the full security pages render, so this sheet cannot say something they do not — and each measured result carries the date it was measured, because a grade without its date is a claim about today that nobody re-earned.
Encryption in transit
- Qualys SSL Labs
- Grade A+ on all four endpoints. TLS 1.2 and 1.3 only — 1.0 and 1.1 are refused. No RC4, forward secrecy with every tested client, and no POODLE, Heartbleed, FREAK or Logjam exposure. Measured 2026-08-17.
- HTTP Strict Transport Security
- Enabled, max-age two years, includeSubDomains. NOT on the browser preload list, and the header does not yet carry the preload directive. Measured 2026-08-17.
Backups and who holds the data
- Cloudflare R2
- Off-site database backups — Full database dumps, which include account records. Object storage
- Cloudflare
- CDN, WAF and TLS termination — All HTTP traffic to the site and API, including request IP addresses. Global edge
- Recovery
- Backups are taken daily, encrypted and off-site. Point-in-time recovery is on the roadmap below and is not in place, so the recovery granularity today is the daily backup, not an arbitrary moment.
What the data contains
- Personal data
- None. What is delivered is market, shareholding and regulatory disclosure data. The TDCC shareholding distribution is banded and aggregate — how many holders and how many shares fall in each band — not identities or accounts. So the data itself does not trigger data-subject obligations.
- Non-public information
- None. Sources are first-hand official disclosure — TWSE, TPEx, TAIFEX, TDCC, MOPS and open macroeconomic sources. We do not scrape third-party sites and do not use expert networks.
- Account data
- Separate from the market data, and it is the part that leaves our systems: full database dumps include account records, which is why the backup row above names what that provider can see.
Access controls
- In use today
- Single sign-on, Roles and least privilege (TWMD operators), Dashboard and credential governance, Human approval for CLI and agent access, Per-call audit records
- Not built
- Role-based access control over data requests, SCIM provisioning — listed because a reviewer needs the absences, not only the presences.
Certification status
We hold no third-party certification. This board is what we have, what is underway, and what has not been started — in that order, and the third column is the one worth reading first.
Done — publicly re-checkable
- Qualys SSL Labs A+ on all four endpoints
- HSTS enabled (not yet on the browser preload list)
- Verifiable proof: public endpoints plus a standard-library verifier
- No material non-public information, no personal data in the market data
- SIG-Lite / CAIQ-Lite self-assessment published in full (a self-assessment, not a third-party certification)
In progress
- GDPR and privacy documentation
- Per-dataset attribution rollout
Roadmap — not started
- Third-party penetration test
- SOC 2
- ISO 27001
- Database encryption at rest
- Point-in-time recovery
Check it yourself
The TLS grade can be re-run by anyone against our public hostnames. The proof mechanism is a set of keyless endpoints and a standard-library verifier that imports nothing of ours. The full self-assessment — including the answers that count against us — is published rather than sent on request.
- Security overview — https://twmarketdata.com/security
- Trust centre — https://twmarketdata.com/trust
- SIG-Lite / CAIQ-Lite self-assessment — https://twmarketdata.com/trust/self-assessment
- Verifiable data — https://twmarketdata.com/security/verifiable-data
- Standards & Interop — https://twmarketdata.com/trust#standards
Printed copies go stale. Every URL above resolves to the current position, and this sheet is generated from the same records those pages render.