Raptor Holdco Gp LLC

08/04/2026 | Press release | Distributed by Public on 08/04/2026 12:57

From Foundations to Maturity: How Templum built a best-in-class cybersecurity program in partnership with Soteria

The Challenge

Templum operates at the intersection of financial technology and capital markets regulation. As the operator of an Alternative Trading System (ATS) through its broker-dealer subsidiary, Templum Markets LLC, and as the ONLY platform holding the combined authorizations of a Qualified Matching System, Broker-Dealer, Transfer Agent, and ATS, Templum handles sensitive financial data and facilitates transactions for a growing network of institutional partners.

That position carries significant security obligations. Institutional clients - investment banks, wealth platforms, RIAs, and asset managers - conduct rigorous due diligence before connecting their infrastructure to a partner's platform. They need more than assurances. They need evidence.

In 2021, Templum had strong foundational security built into its software platform. What it did not yet have was the independently validated, comprehensively documented cybersecurity program that the institutional market expects from a trusted infrastructure partner. The goal was clear: build a mature, best-in-class security program - and prove it.

The Partnership

In May 2021, Templum engaged Soteria - a Charleston, SC-based cybersecurity firm specializing in regulated industries - to provide virtual Chief Information Security Officer (vCISO) services. Rather than a one-time assessment, this was designed as a long-term strategic partnership: Soteria embedded alongside Templum's technology and compliance leadership to build, mature, and validate a security program from the ground up.

The partnership was structured around three objectives:

  • Build a robust, framework-aligned security program. Develop and mature a security program structured around the NIST Cybersecurity Framework and aligned with FINRA regulatory expectations, with clear prioritization based on risk exposure and implementation effort.
  • Achieve independent validation of security controls. Successfully complete the SOC 2 Type 2 attestation process to provide institutional clients with independently verified confidence in Templum's security posture.
  • Maintain continuous threat awareness. Continuously assess the Templum Markets web application and core infrastructure for vulnerabilities through ongoing scanning, cloud configuration reviews, and periodic penetration testing.

Soteria's work spanned four areas:

  • Strategic Advisory. Ongoing guidance on cybersecurity risk, the evolving threat landscape, and the prioritization of security initiatives - providing Templum's leadership with a consistent, expert perspective on emerging challenges.
  • Program Development. Selection and implementation of a security framework aligned with NIST and FINRA standards, establishment of a recurring risk assessment process, and development of a multi-year implementation roadmap.
  • Technical Assessments. Thorough Azure architecture and configuration review, continuous Microsoft 365 security configuration monitoring, and recurring web application and infrastructure penetration tests conducted annually since 2019.
  • Incident Readiness and Recovery Testing. Facilitation of Cybersecurity Incident Tabletop Exercises (TTX) and Business Continuity Exercises to ensure Templum's response to a real incident would be coordinated, effective, and well-rehearsed.

In addition to these areas, we also engaged Soteria's Detection and Response Team (DART) to provide 24/7 managed detection and response (MDR) services, ensuring that any potential incidents would be quickly detected and contained.

The SOC 2 Achievement

The SOC 2 Type 2 attestation was the program's most visible milestone - and among its most demanding. SOC 2 is an independent audit of a company's security controls conducted by a third-party auditor against the AICPA Trust Service Criteria. A Type 2 attestation goes further than a point-in-time snapshot: it evaluates whether controls were not only in place but operating effectively over a defined period - in Templum's case, 12 months. For technology companies handling sensitive client data, SOC 2 Type 2 is widely regarded as the baseline standard of institutional-grade security credibility.

Soteria guided Templum through every stage of the process:

  • Scope definition. Identifying precisely which systems, processes, and data flows would be included in the audit - a critical foundation that shapes the entire assessment.
  • Trust Service Criteria selection. Establishing the specific criteria against which Templum's controls would be evaluated, with Security as the primary focus.
  • Control design and implementation. Defining and implementing a control set that met or exceeded the Trust Service Criteria requirements, ensuring the audit reflected genuine security maturity rather than surface-level compliance.
  • Audit readiness. Preparing Templum's team and documentation for the formal audit process, resulting in a clean SOC 2 Type 2 attestation.

Chris Pallotta, Founder & CEO, Templum Inc: "When institutional partners evaluate Templum as an infrastructure provider, the SOC 2 attestation is one of the first things they look for. It removes a significant question from the room - not because it is a regulatory requirement, but because it is evidence that our security program has been independently tested and validated by a qualified third party. That matters enormously in the markets we operate in."

Glenn Starkman, Co-Founder, Soteria: "Templum approached this process with genuine commitment to getting it right, not just getting it done. The result is a security program that reflects real organizational discipline - the kind that holds up under scrutiny from sophisticated institutional counterparties. The SOC 2 attestation is the proof point, but the program behind it is what we are most proud of."

Templum's Security Posture

The program has produced demonstrable, measurable security strengths across Templum's technical and corporate environments.

Access Management

Templum maintains a rigorous, restrictive access policy built on the principle of least privilege:

  • Privileged Identity Management (PIM) controls privileged access across the environment.
  • Privileged accounts are managed via dedicated administrative credentials, separate from standard user accounts and not configured with email access.
  • All privileged account activity is logged through a unified audit log and monitored in real time by Charleston, SC-based Soteria's MDR solution.
  • Administrative access rights are reviewed on a recurring basis and revoked promptly when no longer required.

Security Leadership

Templum's security program is supported by named leadership with clear ownership across technology, security, compliance, and legal:

Brian Nadzan: Chief Technology Officer & Chief Information Security Officer. Oversees the Templum platform, IT infrastructure, and leads the organization's security strategy and program delivery.

Oscar Gutierrez: Senior Cloud Security Engineer. Manages cloud security architecture, including identity and access (Microsoft 365, Entra, Conditional Access).

Edward Lee: Chief Compliance Officer. Ensures the security program aligns with applicable regulatory and legal requirements.

Roney George: Chief Architect. Manages application and cloud infrastructure security.

Scott Kalish: General Counsel. Provides legal oversight of security program obligations and the organization's regulatory posture.

Chris Pallotta: Chief Executive Officer. Demonstrates executive ownership of cyber risk management and sets the tone for security culture across the organization.

What Comes Next

Achieving SOC 2 Type 2 attestation was a milestone, not a destination. Templum and Charleston-based Soteria continue their partnership with a clear focus on the next phase of maturity:

  • Operational security enhancements. Implementing additional Data Loss Prevention (DLP) controls and expanding formal security baselines and documented procedures.
  • Program documentation and metrics. Ongoing maintenance of the Information Security documentation library and expansion of program metrics reporting to leadership.
  • Incident and continuity planning. Annual review and update of the Incident Response Plan, with new testing scenarios for Business Continuity and Disaster Recovery (BC/DR).
  • Continued assurance. Continued periodic penetration testing and disciplined control tracking for future SOC 2 Type 2 audit cycles.

The program Templum and Soteria have built since 2021 is not a point-in-time achievement. It is a living framework - one designed to evolve alongside Templum's growth, its expanding partner network, and the regulatory environment in which it operates. The SOC 2 Type 2 attestation is the external validation of that framework. The ongoing work is what keeps it credible.

Raptor Holdco Gp LLC published this content on August 04, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 04, 2026 at 18:57 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]