Security & access control

Built with the access-control discipline financial data requires.

You're personally FCA-accountable for how client data is handled. This page is written plainly and factually, so your compliance officer can read it as-is. Where we haven't yet earned a formal certification, we say so rather than implying one.

Server-side session scoping

Every client session is scoped on the server. A client can never reach another client's data — and that boundary is enforced independently of the user interface, not just hidden in the front end. Access is decided where it can't be bypassed.

Directional household visibility

Household visibility is opt-in and directional. An adviser controls exactly who can see whom — one family member can be granted sight of a spouse's or child's portfolio, in one direction only. It is off by default and only the adviser can change it.

Full audit log, real actors

Every login, every document access and every data change is recorded — with real actor identity, not “anonymous.” When your compliance officer asks who saw what and when, the log answers with a name.

Private backend network

The data layer has no public internet exposure. Only the adviser dashboard and the client portal are public-facing — and only over authenticated sessions. Everything behind them sits on a private network.

What we don't claim

We'd rather be trusted than sound impressive.

Plenty of vendors reach for “bank-grade security” or a certification badge they can't substantiate. We won't put a claim on this page until it's true and verifiable.

We do not currently make bare claims of “bank-grade security,” a specific compliance certification, or GDPR compliance as a slogan. If and when a formal certification is in place, it will appear here with evidence — and not before.

What we will stand behind is the architecture described above: scoped sessions, directional visibility, complete audit trails, and a private data layer. For a formal review, we're glad to take your compliance officer through the detail directly.

Talk to us about a compliance review

Bring your compliance questions.

We built Tandem inside a working advice firm, under the same accountability you carry. We expect the hard questions — and we'd rather answer them before you buy.