generated: '2026-08-04' method: searched source: https://freetrade.io/llms.txt docs: https://freetrade.io/legal/mifidpru-disclosures notes: >- Freetrade's published conformance posture is entirely REGULATORY, not technical. It is a UK-authorised investment firm with a full set of published regulatory disclosures, but it exposes no public API, so none of the cross-cutting API standards (OAuth 2.0, OIDC, RFC 9457, JSON:API, OData, SCIM, FAPI, Open Banking) apply — each is recorded below as `conforms: false` with `applicable: false` so a re-run does not read the absence as a technical failure. regulatory: - id: fca-authorisation conforms: true regime: UK Financial Conduct Authority identifier: 'FRN 783189' evidence: https://register.fca.org.uk/s/firm?id=001b000003rtZg9AAE - id: lse-member-firm conforms: true regime: London Stock Exchange evidence: 'Member firm of the London Stock Exchange (freetrade.io/llms.txt)' - id: mifidpru-ifpr conforms: true regime: UK Investment Firms Prudential Regime (MIFIDPRU) evidence: https://freetrade.io/legal/mifidpru-disclosures - id: mifid-order-execution conforms: true regime: Best execution / order execution policy evidence: https://freetrade.io/legal/order-execution-policy - id: mifid-execution-venues conforms: true regime: Execution venue disclosure evidence: https://freetrade.io/legal/execution-venues - id: conflicts-of-interest-policy conforms: true regime: FCA SYSC conflicts of interest evidence: https://freetrade.io/legal/conflicts-of-interest - id: fscs-protection conforms: true regime: Financial Services Compensation Scheme evidence: 'Deposits protected up to £120,000 per person per institution; investments up to £85,000 (freetrade.io/keeping-you-safe)' - id: uk-gdpr conforms: true regime: UK GDPR / Data Protection Act 2018 evidence: https://freetrade.io/legal/privacy-notice - id: hmrc-isa-manager conforms: true regime: HMRC ISA / Junior ISA rules evidence: https://freetrade.io/isa-terms-and-conditions - id: fca-consumer-duty conforms: true regime: FCA Consumer Duty (customer charter) evidence: https://freetrade.io/legal/freetrade-customer-charter - id: sweden-regulated-entity conforms: true regime: Regulated in Sweden as well as the UK evidence: 'Reported at acquisition; not independently confirmed from a Freetrade-published page' confidence: low standards: - {id: openapi, conforms: false, applicable: false, evidence: 'no public API contract published'} - {id: asyncapi, conforms: false, applicable: false, evidence: 'no public event/webhook surface'} - id: graphql conforms: false applicable: true evidence: >- A live GraphQL gateway exists at https://core-service-gateway.freetrade.io/graphql (found in the web.freetrade.io CSP connect-src), but anonymous introspection is explicitly disabled (INTROSPECTION_DISABLED) and no SDL, documentation, onboarding or third-party access terms are published. Private implementation surface, not a published GraphQL API. - {id: oauth2, conforms: false, applicable: false, evidence: 'no public authorization server; /.well-known/oauth-authorization-server 404'} - {id: oidc, conforms: false, applicable: false, evidence: '/.well-known/openid-configuration 404 on every host'} - {id: rfc9457-problem-details, conforms: false, applicable: false, evidence: 'no public API'} - {id: rfc9116-security-txt, conforms: false, applicable: true, evidence: '/.well-known/security.txt 404 on freetrade.io and web.freetrade.io; the only 200 is Intercom''s vendor file on the help host'} - {id: rfc8615-well-known, conforms: false, applicable: true, evidence: 'no first-party /.well-known/ documents'} - {id: llms-txt, conforms: true, applicable: true, evidence: 'https://freetrade.io/llms.txt — hand-curated, dated, with explicit model-guidance notes; second llms.txt on the Intercom help host'} - {id: mcp, conforms: false, applicable: true, evidence: 'no hosted MCP server; mcp.freetrade.io NXDOMAIN'} - {id: a2a, conforms: false, applicable: true, evidence: '/.well-known/agent-card.json and /.well-known/agent.json 404 on every host'} - {id: open-banking-obie, conforms: false, applicable: false, evidence: 'investment brokerage, not a PSD2/CMA9 account provider'} compliance_certifications: published: false note: >- No SOC 2, ISO 27001, PCI DSS or trust-centre page is published on any Freetrade host (trust.freetrade.io and security.freetrade.io are NXDOMAIN). The security page describes controls (app PIN, biometrics, MFA, access controls, daily reconciliation with third-party audit by PwC) but names no certification. security_page: https://freetrade.io/keeping-you-safe x-evidence: fetched: '2026-08-04' sources: - {url: 'https://freetrade.io/llms.txt', http_status: 200} - {url: 'https://freetrade.io/legal/mifidpru-disclosures', http_status: 200} - {url: 'https://freetrade.io/keeping-you-safe', http_status: 200}