A founder picks a platform, agrees pricing, and then gets sent a due diligence questionnaire. Corporate documents, ownership chart, licence details, target markets, AML policy. The reaction is usually the same: you are selling me software, why do you need my UBO chart.
The answer is that a platform vendor sits inside several chains at once, and each of them applies pressure. Its own bank processes your subscription payments. Its market data agreements carry redistribution terms. If it operates mobile apps on your behalf, it faces app store review. If it hosts your instance, it holds personal data of your clients and inherits data protection obligations. And in some arrangements the vendor is not only a supplier but a party in the regulatory picture, which changes everything about what it needs to know.
The white label question underneath the checks
Most vendor scrutiny traces back to one distinction: is the vendor supplying technology to a firm that holds its own permissions, or is the firm operating under someone else's authorisation. Those are different products with different obligations, and they get confused constantly. White label licence myths is worth reading in full, because the phrase gets used for arrangements that range from a rebranded front end to an introducing relationship where the regulated firm carries the client.
Where a regulated firm's permissions are involved, that firm has outsourcing obligations to its regulator. It has to assess the supplier, control the arrangement, retain responsibility for client outcomes and be able to exit. Those obligations flow down as questions to you and to the vendor. Where the arrangement is genuinely software only, the vendor's checks are narrower but they do not disappear.
What a vendor typically verifies
Legal entity and ownership to natural persons, screened against sanctions lists. Licence or registration status, checked on a public register rather than accepted as a PDF. The countries you intend to accept clients from, and the ones you will exclude. Your marketing approach, particularly for retail derivatives, because marketing restrictions differ sharply by jurisdiction and a vendor does not want its product named in a promotion that breaches them. And your data handling, if client personal data will sit in the vendor's infrastructure.
The output of those checks is not usually a yes or a no. It is a set of conditions: which instruments can be enabled, which leverage tiers, which countries are blocked at signup, and what disclosures appear in the client interface. A vendor that configures leverage caps and risk warnings by client jurisdiction is not being difficult. It is doing what the EU intervention measures and equivalent rules elsewhere require of the firms it serves.
Why some jurisdictions narrow your platform choices
Take positions honestly here. A firm registered somewhere with a company registry and no meaningful supervision of investment services, marketing to EU or UK retail clients, will find several parts of the stack unavailable. Not because platform software is regulated, but because every adjacent party runs its own risk assessment: the payment processor, the market data provider, the app stores, the ad platforms. The platform vendor knows this and does not want a customer who will fail three months in and dispute the invoices.
The reverse is also true and worth saying. A modest but genuinely supervised licence, matched to the markets you actually serve, opens more of the stack than an impressive-sounding registration that no counterparty recognises. That is a structural argument, and it is settled at incorporation, not at platform selection. Founders comparing routes should look at how licence routes compare alongside what offshore registrations confer.
General description only. Vendor requirements, outsourcing rules and permitted marketing differ by jurisdiction and by contract, and every firm needs its own legal and compliance advice on what it may operate and where.
What to ask the vendor in return
Due diligence runs both ways, and most brokers under-ask. Which entity contracts with you and where is it incorporated. Where is client data hosted and processed, and does that satisfy your own data residency obligations. What are the audit and reporting capabilities, because your regulator will ask for records the platform holds. What is the exit path: can you export client records, trade history and open positions in a usable format, on what notice, and at what cost. Who is liable when the platform is unavailable during a market event.
The exit question is the one that decides how much power you have later. A firm that cannot leave has no negotiating position on price, roadmap or terms, and vendor lock-in in this sector is normally created by data formats rather than by contracts. Ask for the export specification before you sign, not after.
Where SINGUARD sits in this
We build software: the eTrader platform, a Broker CRM and a Prop Firm CRM, supplied by SGHK Softwares Limited in Hong Kong, with SINGUARD GLOBAL FZC in Ajman Free Zone as our UAE entity and the team working out of Dubai. We hold no financial services licence anywhere and we do not lend permissions to anyone. Each firm we supply is responsible for its own licensing, its own client money and its own compliance, and our onboarding checks exist so we understand what we are configuring and for whom. Anyone deciding on a stack should read how to choose a trading platform with the licence question in front of the feature list rather than behind it.
"People assume the platform is the easy part and the licence is the hard part. In practice the licence decides which platforms will even quote you, which makes it the first decision, not the last."
— Alex Onta, Executive Director, SINGUARD
Key Takeaways
- Vendors run checks because banks, data providers, app stores and ad platforms all apply their own risk assessments down the chain.
- The central question is whether you hold your own permissions or operate under someone else's, because outsourcing obligations differ sharply.
- Checks usually produce conditions rather than refusals: country blocks, leverage tiers, instrument limits and required disclosures.
- Ask about data hosting, audit records and the export path before signing, because data formats create lock-in more often than contracts do.
Frequently Asked Questions
Is trading platform software itself regulated?
The software is generally supplied as technology rather than as a regulated financial service, but the firms using it are regulated, and their outsourcing obligations plus adjacent counterparties create the checks. Confirm your own position with your legal advisers.
Why would a vendor restrict which countries we can accept clients from?
Because retail derivatives rules, marketing restrictions and leverage limits differ by country, and a vendor configuring a live platform does not want its product used for activity that is unauthorised where the client sits.
What should we ask a platform vendor before signing?
Which entity contracts with you, where client data is hosted, what audit and reporting exports exist, what happens during an outage, and exactly how you would export client records, trade history and open positions if you left.
About the Author
Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.