BSX · Public information
Security and trust
BSX verifies participating organisations, controls user access and records every material action in the transaction.
The platform is in development. Identity controls, document integrity, operational procedures, legal review and independent security testing must be completed before trading begins.
Risk-based verification
Participation begins with due diligence on the organisation and the people who own, control, and represent it.
Legal identity
Registration, current standing, address, business activity, and the expected purpose of participation.
Ownership and control
Direct and indirect ownership, beneficial owners, controlling persons, and supporting evidence.
Representatives
Identity, role, authority to bind the organisation, and transaction permissions.
Risk review
Sanctions and other required screening, source information where relevant, and ongoing review proportionate to risk.
- FATF Recommendations
International risk-based customer-due-diligence framework.
Access follows responsibility
Users should see and perform only the work assigned to their organisation and role.
Identity, multi-factor authentication, organisation membership, transaction assignment, and action-level permissions form separate controls. Sensitive changes and release-related actions require a second authorised person.
Document and record integrity
Every material submission and decision should be attributable and resistant to silent alteration.
Attribution
Organisation, user, source, and authority are attached to the action.
Versioning
A correction creates a new version without erasing the superseded submission.
Integrity evidence
Cryptographic hashes and controlled storage help detect later alteration.
Audit history
Material actions, reviews, timestamps, statuses, and reasons are appended to the record.
Funds remain outside BSX
BSX is not a bank and does not hold, safeguard, or manage client money.
Any funds movement would be executed by licensed financial institutions under their own authority and controls. BSX exchanges structured instructions, evidence, status and confirmation. It does not provide custody or a bank account.
Assurance before launch
Controls must be tested and evidenced before they can be trusted in operation.
Security testing
Independent penetration testing and remediation before launch, followed by periodic reassessment.
Operational readiness
Incident response, continuity, recovery, support, escalation, and change-control procedures.
Supplier assurance
Due diligence, contracts, access boundaries, and monitoring for critical service providers.
Evidence and review
Control operation should be recorded and available for independent review.
Public information
Understand participation
Review who the platform is for, the information requested, and how an organisation file is assessed.