Trust centre
Everything a procurement or compliance team needs to assess MPS Compare in one place. Every control on this page is in place and operating today: we do not list certifications we have not obtained or features we have not shipped.
One-paragraph posture
MPS Compare is a UK-hosted research and projection platform for FCA-authorised financial advisers. Personal data is restricted to adviser user accounts; the schema deliberately accepts no client identifier. Every research output is recorded in an append-only audit trail backed by database-level deletion grants; historical figures cannot be amended in place. Tenant isolation is enforced by PostgreSQL Row-Level Security, tested on every release. We do not provide investment advice; we provide infrastructure for advisers who do.
Infrastructure & data protection
Database and object storage hosted in Supabase eu-west-2 (London). Application served from a CDN edge pinned to LHR1 (London). No US-region routing.
TLS 1.2+ on every connection. HSTS with preload on the public surface.
Database storage and object storage (generated PDFs) encrypted at rest by the managed provider.
Every multi-tenant table carries an explicit PostgreSQL Row-Level Security policy keyed on the firm identifier, resolved server-side from the authenticated session. Integration tests sign in as Firm A and assert zero rows when probing Firm B.
Ten export audit tables. Audit records can be written and read, never amended or removed; this is enforced by database-level permissions rather than application code. The 7-year retention floor is enforced by the absence of any deletion path.
All factsheet snapshot tables (performance, allocation, sector, region, factor, fees, holdings, annual returns) are immutable once written: amendment and removal are blocked by database-level permissions. Corrections create a new dated row.
Every PDF export records its engine or PDF generator version, the methodology document version, and a SHA-256 integrity hash computed over the exact stored PDF bytes, so an auditor can re-download the archived file and prove it is byte-for-byte unaltered.
Schema-enforced. No column on any table accepts a client-attributable value. The platform does not provide client-management features.
pnpm audit and Dependabot run in CI; the build fails on high or critical advisories without an explicit waiver. Lockfile committed; deterministic installs.
Identity & access
Supabase Auth. NIST SP 800-63B-aligned password rules enforced in the application (12-character minimum, length over complexity).
Self-service enrolment with any RFC 6238 authenticator app (Microsoft Authenticator, Google Authenticator, 1Password, Authy). Mandatory for staff and firm administrators: enrolment is required at sign-in, enforced server-side on every privileged surface, and an enrolled account verifies a code on each sign-in.
Per-IP throttling and a per-account lockout on sign-in, enforced server-side with counters held in the UK-resident database. A CAPTCHA challenge (Cloudflare Turnstile) protects the sign-in and password-reset forms. Provider-level rate limits apply beneath.
Sign-ins, failed attempts, lockouts, password changes and MFA changes are recorded to an append-only ledger with no client read or write access at the database. Firm administrators review their own firm's events on the admin panel Security view.
Three roles per firm (admin, IFA, paraplanner) with a documented capability matrix on the firm-admin Compliance tab.
Legal & compliance documents
- Privacy notice
UK GDPR-compliant. What we collect, why, retention, your rights.
- Terms of service
Self-service terms covering scope, AUP, IP, billing, liability, governing law (E&W).
- Data processing agreement
UK GDPR Article 28 processor-controller terms. Incorporated into the terms of service by reference.
- Sub-processors register
Authoritative public list of third parties we use to deliver the service.
Regulatory framework
MPS Compare is an unregulated technology vendor. We provide research aids to FCA-authorised firms; suitability and investment advice remain the authorised firm's responsibility. The platform's controls support the following FCA reference points:
- COBS 4 / 6 / 9 / 9A: outputs are explicitly marked as research and projection aids, not communications or personal recommendations.
- COBS 13 / 14 (product information): factsheet sources and snapshot URLs recorded against every performance snapshot. PRIIPs disclosures are transitioning to the FCA's Consumer Composite Investments regime (DISC sourcebook) between 6 April 2026 and 8 June 2027.
- COBS 16 (reporting): audit trail and per-row PDF download support reproducible client reports.
- COBS 19 (pensions / drawdown): Income tool records full input set, parameters, and the probability of depletion.
- SYSC 9.1 (record-keeping): 7-year retention floor enforced by database deletion grants on audit-trail tables and stored PDFs.
- SYSC 4 / 7 (organisational requirements and risk control): append-only audit, immutable snapshots, deterministic calculation engine, RLS tenant isolation, hashed firm API keys.
- PS21/3 (operational resilience, for firms in scope): the platform's hosting, availability and recovery arrangements are evidenced on request for firms mapping their important business services.
We provide infrastructure controls, not legal compliance advice. Always review your firm's specific obligations with your compliance officer.
Reporting a vulnerability
Security researchers acting in good faith can report vulnerabilities to security@mpscompare.co.uk. We commit to acknowledging reports within 72 hours and to remediating critical vulnerabilities within 30 days.
Security questionnaires & enterprise engagement
If your firm's onboarding requires a completed security questionnaire (SIG Lite, CAIQ, VSA Core, or your firm's own format) or specific procurement documentation, contact trust@mpscompare.co.uk. We aim to respond within five working days.
For data-protection enquiries, including controller / processor questions and data-subject rights, contact privacy@mpscompare.co.uk.
What this page does not claim
Trust centres that pad their control lists with aspirations are common in this market and do not survive a procurement reviewer's second read. This page lists no certification we have not obtained and no control we have not shipped: everything above is operating today and can be evidenced on request. When something new lands, it is added here, and the date at the top moves.