Uvistium
Home / Security
The full architecture

Security at institutional grade.

How your capital, your credentials, and your personal data are protected. Concrete standards, auditable certifications.

Encryption — standard and application

Your data is encrypted at rest with AES-256. Traffic between your browser and our servers is carried exclusively over TLS 1.3 with forward secrecy. Legacy cipher suites are not supported; TLS 1.2 remains available only with modern ECDHE suites for older client compatibility.

Authentication

Two-factor authentication is mandatory. Available methods: TOTP (Google Authenticator, Authy, 1Password) or WebAuthn (YubiKey, Face ID, Touch ID, Windows Hello). SMS-based codes are structurally not offered — SIM-swap attacks make SMS unsuitable as a second factor.

WebAuthn recommended for accounts above £25,000. WebAuthn with a hardware key is phishing-resistant. Even if you were to enter your credentials on a spoof Uvistium site by accident, the attacker cannot present your hardware key to our systems.

Client-fund segregation

Uvistium never holds client funds directly. All deposits are routed via Faster Payments, BACS, or CHAPS straight to an FCA-authorised Tier-1 broker partner, which holds them in a segregated client account under the CASS 7 client-money rules. These accounts are strictly ring-fenced from the broker's own funds.

In the event of a broker partner's insolvency, your holdings are protected up to £85,000 per client, per authorised institution by the Financial Services Compensation Scheme (FSCS). For accounts above £85,000, we split placements across multiple broker partners to multiply the effective FSCS protection.

Certifications and audits

Internal access control

Zero-trust architecture. All access to production systems requires hardware-based 2FA and is time-limited (just-in-time access). No employee — including the board — has standing access to client data. All access is recorded in an immutable log system and audited internally on a quarterly basis.

Business continuity

Production data is held in two geographically separated Tier-3 data centres in London and Manchester. Backup snapshots every 15 minutes, retained for 90 days. Recovery time objective (RTO): 4 hours. Recovery point objective (RPO): 15 minutes. Both facilities are BS EN 50600-3 certified.

Data protection under UK GDPR

Uvistium is fully compliant with the UK GDPR and the Data Protection Act 2018. Your personal data is used solely to deliver the wealth-management service and is never sold to third parties. You retain the right to access, rectify, erase, and port your data at any time — see our privacy notice.