A trading platform sits under a regulator that asks specific questions and expects specific evidence. The technical work matters, but the reason engagements like this succeed or fail is usually the governance layer, because that is where the regulator looks first.
The gap between secure and demonstrable
Marketwolf's platform was not insecure. Most of the initial gap sat in the distance between controls that operated and controls that could be shown to operate to somebody who was not in the room. A policy that exists but was last reviewed two years ago, an access review that happens informally, an incident process that lives in the heads of three people.
SEBI's framework is explicit about governance, and the finding pattern reflects that. We ran the gap assessment against the framework clause by clause and separated the findings into two lists: things that needed building, and things that needed evidencing.
The technical assessment
Trading platforms carry a specific risk profile. Order manipulation, race conditions around order state, and authorisation between accounts matter more than they would on a content platform, because the exploit outcome is financial and immediate.
Mobile was in scope alongside web and API, since a retail platform's real attack surface is the app most users hold rather than the site.
Governance work
We wrote and reworked the artefacts the framework requires: incident response with named owners and escalation timing, access control policy with a review cadence that actually happens, third party risk covering the vendors in the critical path.
The test of whether this work landed is not the document. It is whether the second access review, six months later, still happened without us.
What was handed over
The gap assessment mapped to framework clauses, technical findings with reproduction and retesting, the governance artefacts, and an evidence pack organised the way the regulator asks for it.













