Our posture
CLEO is operated by CLFNCE OÜ, a company incorporated in the Republic of Estonia. While CLEO itself is infrastructure software - not a regulated financial institution - we design the platform so that our customers (prop firms and brokers) can meet their own obligations without fighting their vendor.
Frameworks we align with
GDPR - Regulation (EU) 2016/679
We process personal data as controller for our direct customer relationships and as processor on behalf of prop firm and broker customers for their end-users. Data processing agreements are available to all paying customers. See our Privacy Policy for details on lawful bases, rights, and international transfers.
MiFID II - Directive 2014/65/EU
Where our customers are MiFID-regulated investment firms, CLEO supports the operational requirements they pass through to us: timestamped order audit trails, best-execution records, algorithmic and DMA controls, transaction reporting feeds, and segregation of client data.
DORA - Regulation (EU) 2022/2554
The Digital Operational Resilience Act took effect on 17 January 2025. As an ICT third-party service provider to financial entities, we support our customers' DORA obligations through:
- Contractual terms that include the mandatory DORA clauses.
- Incident notification SLAs and a documented response playbook.
- Business continuity, disaster recovery, and RTO/RPO commitments aligned with financial-services expectations.
- Regular penetration testing and threat-led resilience exercises.
EMIR - Regulation (EU) 648/2012
For customers reporting derivatives under EMIR, CLEO retains and exports the trade-level data points required for reconciliation with trade repositories. Reporting itself remains the counterparty's regulatory responsibility.
AML / KYC
CLEO is not itself an obliged entity under Estonia's Money Laundering and Terrorist Financing Prevention Act, but we provide tooling that lets obliged customers carry out their own KYC / KYB: identity verification integrations, ongoing monitoring signals, sanctions list checks, and SAR-ready audit exports. We follow FATF guidance in the design of these controls.
Operational security
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access control with least-privilege defaults and mandatory MFA for staff.
- Segregated production and non-production environments, with no shared credentials or data.
- Centralised, tamper-evident audit logging retained for at least 12 months.
- Annual external penetration tests and continuous vulnerability management.
Business continuity
Our infrastructure is deployed across multiple availability zones with automated failover. We target 99.9% monthly uptime, run regular restore drills, and document RTO/RPO commitments in enterprise contracts.
Responsible disclosure
If you believe you have identified a security vulnerability in CLEO, please report it to security@cleo.finance before any public disclosure. We investigate every report and coordinate in good faith.
Get the documentation
Enterprise customers and prospects under NDA can request our sub-processor list, DPA, security whitepaper, and DORA package by contacting compliance@cleo.finance.