What the examiner asks for — written, rule-mapped, ready to adopt.
An exam notice requests specific records. Premium gives you the starting documents and the tools that build them — your firm adapts, approves, and implements.
- Vendor due diligence file Vendor portal with researched records on 600+ providers. Select your stack, export the decision pack, sign and file.
- Written policies 60 templates, the ones MTradecraft uses in its own engagements
- Training records FieldCraft training with completion records
- Incident response plan IRP Builder writes the plan. The Incident Response Assistant walks you through an incident when it happens.
- Vulnerability assessment records Quarterly External Vulnerability Scan of your public footprint, summarized against Reg S-P and Reg S-ID. Nothing to install.
- AI use policy and oversight AI Compliance Framework, governance workbook, output validation protocol, and an AI track in the vendor portal. Written by a firm that runs AI in its own practice.
The vendor file first. Then the rest of the evidence.
Most firms come for the vendor due diligence portal. Premium packages it with the other evidence an SEC-registered firm is asked to show — that it trains its people, can respond to an incident, and has written the policies — and the tools that build it.
The Reg S-P vendor file, already researched. You decide and sign.
Search 600+ vendors RIAs actually use. Each record carries a plain-language assessment and every sourced answer with its citation and capture date; anything without a public source stays marked Unknown, and a SOC 2 held under NDA is noted as listed, not obtained. Select the vendors in your stack and export the decision pack: one executive page across every vendor, one decision sheet per vendor, clickable source links, and an Excel workbook of the same evidence. Your CCO records the decision and signs. MTradecraft does not approve or reject vendors.
The executive page of an exported decision pack (sample firm, three vendors).
Vendor missing? Email vdd@mtradecraft.com and we research it, forward the vendor our self-report form, or send us their SOC 2 report or ISO certificate.
Security awareness, with the records
Phishing simulations, quiz tracking, and audit-ready completion reports for up to 50 employees — the training evidence that supports your Reg S-P safeguards program.
The plan before, the record during
Answer five minutes of questions; the IRP Builder generates your firm-specific Reg S-P incident response plan as an editable Word document, every section mapped to §248.30. If an incident starts, the Incident Response Assistant walks you through it step by step and produces a timestamped incident record for the firm’s Reg S-P and Rule 204-2 documentation.
Document how your firm governs AI
The AI Compliance Framework, governance workbook, output validation protocol, and AI marketing claims checklist — plus an AI supplemental track inside the vendor portal.
See what the internet sees — every quarter
A passive scan of your firm’s public exposure — look-alike domains, forgotten subdomains, email-spoofing gaps, exposed services — summarized against Reg S-P and Reg S-ID. Nothing to install; tell us your domains once.
Two tiers. One Premium price.
Free puts real material in your hands today — the exam report, the mock exam, the review matrix, every Insight. Premium is the full library and the tools that build the documents: $2,500 a year, flat, cancel anytime, access through the end of the paid period.
The BrainTrust
A practical starting point for firms that need better direction before engaging a consultant or building a more formal cybersecurity compliance program.
- Securing Compliance — what SEC examiners actually ask for
- Mock SEC Cyber Exam — 30 real request-list items, scored
- Cybersecurity Compliance Document Review Matrix
- SEC Exam Cybersecurity Preparedness Brief
- Reg S-P 2024 Compliance Impact Summary
- Every Insight — cybersecurity commentary and SEC enforcement updates
The BrainTrust — Premium
For firms that want the documents the examiner asks for already drafted and rule-mapped — and do not yet need MTradecraft to operate the program for them.
- Vendor due-diligence portal — 600+ researched vendors, every answer cited to a public source or flagged for attestation; select your stack and export the Word decision pack and Excel workbook for your Reg S-P vendor file
- FieldCraft security awareness training — phishing simulations and completion records for up to 50 users
- Incident Response Plan Builder and the Incident Response Assistant — the plan before, the timestamped record during
- 60 editable templates across 13 categories — each mapped to the rule it supports
- AI governance kit — framework, workbook, output validation protocol, marketing claims checklist
- Quarterly External Vulnerability Scan — a passive scan of your public footprint every quarter, summarized against Reg S-P and Reg S-ID
- Direct Access — email MTradecraft with cybersecurity compliance questions
- Everything in the Free tier
By subscribing you agree to the BrainTrust Member Policy.
The same materials our engagements run on.
Built in practice, not for the shelf
Premium is the library and tools MTradecraft’s consulting engagements are built on. A full engagement ($36,000) adds firm-specific drafting, independent testing, remediation tracking, and a maintained evidence file; the materials are the same.
They are written by Brian Hahn, who carried chief compliance officer responsibilities at SEC-registered firms and took a firm through an SEC examination with no material findings. Every template cites the rule it supports — Reg S-P, Rule 206(4)-7, Rule 204-2 — and is revised as rulemaking and examination priorities move.
Email support from the practice, not a help desk
Premium members email MTradecraft directly with cybersecurity compliance questions — which template applies, how a rule reads, how to adapt a document to the firm. Answers come from the people who wrote the materials.
It is a resource subscription, not a consulting relationship: no firm-specific drafting, no examination representation, and MTradecraft cannot be named as your cybersecurity expert or CISO. Those are engagements.
Maintained as the rules change — and cited to them.
The BrainTrust is not a marketing handout. Every template cites the specific rule it supports — Reg S-P, Rule 206(4)-7, Rule 204-2 — and the library is revised as SEC rulemaking and examination priorities move, so the version you download reflects current requirements.
Cybersecurity Policies & Procedures Manual (Reg S-P), NPI Data Inventory, Access Control & MFA, Annual Risk Assessment, Data Disposal.
Incident Response Plan, Tabletop Exercise Kit, Wire-Transfer & Disbursement Verification — plus the interactive IRP Builder and the Incident Response Assistant for use during an incident.
AI Compliance Framework & Governance Workbook, AI Output Validation Protocol, AI Marketing Claims Review Checklist.
Vendor Due-Diligence Questionnaire and Confidentiality Agreement — alongside the 600-vendor evidence portal.
206(4)-7 Annual Review, Compliance Calendar, Compliance Meeting Agenda.
Code of Ethics, Conflicts of Interest, Gifts & Entertainment, Political Contributions, Outside Business Activity.
Client Communication Letter Suite, Form ADV Amendment Checklist, Reg S-ID Red Flags.
Marketing Procedures Policy, Firm & Employee Social Media Policies, Promoter & Solicitor Oversight.
Best Execution Evaluation, Trade Error Policy & Log, Proxy Voting, Custody Rule Compliance Checklist.
Employee Technology Use Agreement, Whistleblower Policy, and acknowledgement forms.
Business Continuity Plan, Books & Records Policy, Written Supervisory Procedures.
SEC Exam Document Production Checklist, First-Time Examination Guide, Cybersecurity Request Bundle.
60 editable templates across 13 categories, each mapped to the rule it supports. Browse the full library →
Built for firms in a specific situation.
A Premium membership fits if…
- You are a CCO or IT manager at an SEC-registered firm and you need real policy templates — not generic ones.
- You are a small RIA without the budget for a $36K consulting engagement but with examination obligations you cannot ignore.
- You have an examination, an insurance renewal, or a client DDQ on the calendar and need the written program and evidence file in place before it arrives.
- You want to run FieldCraft Security Awareness Training for your staff without a separate training vendor relationship.
Premium is not the right fit if…
- You need someone else to operate the cybersecurity program, not just provide the documentation. The Cyber Compliance Consultant engagement exists for that.
- An insurance carrier or DDQ requires a named CISO. The Remote CISO engagement exists for that.
- You want active SEC examination support and direct involvement from cybersecurity counsel. That is consulting, not membership.
- You are a compliance consultant who wants to use the library in paid work for your own clients. Membership is licensed for one firm’s internal use; consultants are served under a separate Consultant license — book a call to set one up.
Questions members ask before subscribing.
Can I cancel anytime?
Yes. The subscription is managed through Memberful. You can cancel future charges at any time from your account portal — no phone calls, no penalty. You retain access through the end of the paid period.
Are the documents customized to my firm?
No. BrainTrust templates are provided as editable Word documents that the member adapts to their firm's specifics. If you need documents drafted to your firm, that is a Cyber Compliance Consultant engagement.
Can I list MTradecraft as my cybersecurity expert?
No. A BrainTrust membership is a resource subscription, not a consulting relationship. For DDQ and examination purposes requiring a named cybersecurity expert or CISO, the Remote CISO engagement is what's required.
What does FieldCraft cost beyond 50 users?
The Premium membership includes FieldCraft for up to 50 users. If your firm exceeds 50 users, additional seats can be added on a separate FieldCraft subscription at $4.00 per user per month (billed annually).
Does MTradecraft hold our client data?
No. MTradecraft does not collect, store, or process client customer PII, account numbers, or trading records to provide the membership, and mtradecraft.com keeps no member passwords or payment data (Memberful and Stripe handle billing). That is also why MTradecraft holds no SOC 2 report: there is no customer-data system for one to attest over. For your own vendor file, see MTradecraft’s record in the vendor portal and the published Security Policy.
Will the templates pass an SEC examination?
Templates do not pass examinations — implemented programs do. A BrainTrust template gives you a defensible starting point written by a knowledgeable party. Whether your firm passes an exam depends on how the policies are adopted, implemented, reviewed, and documented over time.
Premium is $2,500 a year — and starts the moment you subscribe.
Free account first if you want to read the Securing Compliance report and access our posts. Upgrade to Premium when the exam notice, the carrier questionnaire, or the client DDQ makes it real.
By creating an account or subscribing you agree to the BrainTrust Member Policy.