Compliance

Designed for your examiners, not just your engineers

Eko ships a full regulatory documentation package with every integration. FINRA, BSA-AML, GLBA, CRA, KYC/CIP — written for bank compliance teams.

Request Compliance Package

Regulatory Framework

The regulatory landscape for community bank investment programs

FINRA Rule 4511 requires member firms to make and preserve books and records as required under the FINRA rules, the Exchange Act, and applicable Exchange Act rules. Eko's platform generates and preserves all required order records, account records, and trade confirmations in the required format. The compliance package includes a pre-written Rule 4511 compliance policy template reviewed against current FINRA examination guidance.

The BSA requires financial institutions to assist government agencies in detecting and preventing money laundering. Eko's platform includes automated AML transaction monitoring with configurable alert thresholds. The compliance package provides a written AML program template, SAR filing procedures, and escalation workflow documentation. Eko's monitoring covers the investment account activity layer — your existing BSA program covers the deposit side.

GLBA requires financial institutions to explain how they share and protect customer nonpublic personal information. Eko processes investment account data under a data processing agreement that specifies data use, retention, and deletion procedures. The compliance package includes updated privacy notice language for your institution's customer disclosure covering the investment account data collected by Eko on your behalf.

The Community Reinvestment Act encourages banks to serve the credit and investment needs of all segments of their communities, including low- and moderate-income neighborhoods. Eko's fractional share capability enables investment minimums as low as $1, making investment products accessible to lower-income households. The compliance package includes CRA investment credit documentation templates that can be submitted as evidence of community development services to examiners.

KYC/CIP requirements for investment accounts require collecting name, date of birth, address, and identification number at account opening. Eko's KYC module handles document collection, identity verification, and CIP record retention. The compliance package includes the CIP written program template and a workflow diagram mapping each step to the applicable regulatory requirement — ready for examiner review.

Certain investment-related cash movements may trigger state money transmitter license requirements. Eko's legal team has analyzed the regulatory landscape in all 50 states. The compliance package includes a state-by-state summary of applicable money transmitter considerations for community bank investment product launches, with guidance on which activities fall under Eko's existing licenses versus your institution's exemptions.

Documentation Package

What ships with every Eko integration

The compliance documentation package is included in all plans — not a separate purchase. Every document is reviewed by Eko's compliance team before delivery and updated when regulatory guidance changes.

  • FINRA workflow mapping document — step-by-step process diagrams
  • AML written program template — pre-filled with Eko-specific procedures
  • KYC/CIP written program template
  • Examiner Q&A guide — anticipated examiner questions with model answers
  • GLBA privacy notice language update
  • CRA investment credit documentation template

Growth Plan — Additional

  • Examiner prep sessions — live walkthrough with Eko compliance team
  • Annual regulatory update review — package updated for exam cycle
  • Dedicated compliance relationship manager

Security

Security practices built for regulated financial data

Eko is a platform/infrastructure provider, not a licensed broker-dealer. Security controls are designed with SOC 2 criteria in mind.

Encryption at Rest and in Transit

All data at rest encrypted with AES-256. All data in transit over TLS 1.3. Encryption key management via AWS KMS with key rotation policies.

Role-Based Access Control

Granular RBAC across all API operations. Institution-level isolation — your data is never accessible to other institutions. Audit logs for all data access events.

SOC 2 Controls in Design

The platform is designed with SOC 2 Trust Service Criteria in mind. Security, availability, and confidentiality controls are documented and reviewed annually. Note: Eko is not currently a SOC 2 Type II certified organization.

Infrastructure Isolation

Production workloads run in isolated VPCs with no shared infrastructure between institutions. Separate compute and storage per institution on Enterprise plan.

Audit Logging

Immutable audit trails for all API requests, data access events, and configuration changes. 7-year retention aligned with FINRA record-keeping requirements.

Data Processing Agreement

A signed DPA is available for all customers, specifying data use, retention periods, subprocessors, and deletion procedures — required for your GLBA compliance documentation.

Request the full compliance documentation package

Our compliance team will walk your compliance officers through the package before you sign anything.