Envestnet, Dataphile, Croesus
Workstation, browser, identity, and secure-access configuration for investment dealers and wealth managers. Integration with document management and MFA-gated portals.
Industry IT · Vancouver, BC
Financial services firms in Vancouver sit on top of some of the most regulated IT in the country. Investment dealers and advisers answer to BCSC, CSA, and CIRO. Mortgage brokers and insurance brokerages answer to BCFSA. MSBs report to FINTRAC. Federally regulated firms answer to OSFI and FCAC on top. Client data segregation, audit trail retention, and privileged access management are not nice-to-haves, they are examination findings if they are missing. Hexafusion supports Lower Mainland financial services firms with examination-ready IT, 15-minute ticket response, and a founder whose PCI DSS Internal Security Assessor background maps directly onto the kind of evidence regulators ask for.
Workstation, browser, identity, and secure-access configuration for investment dealers and wealth managers. Integration with document management and MFA-gated portals.
Mortgage broker platforms. Tenant configuration, user access, secure client-document exchange, and integration with CRM and accounting.
Insurance brokerage management systems. Server or cloud deployment, user provisioning, carrier-portal connectivity, and secure document workflows.
Salesforce Financial Services Cloud, Redtail, Wealthbox, NaviPlan, Conquest. Tenant and integration configuration with least-privilege access.
NetDocuments, Citrix ShareFile, ShareFile, or equivalent with expiring links, access logging, and MFA in place of email attachments.
Microsoft 365 in Canadian regions, Azure Canada Central for hosted workloads, and conditional-access policies scoped to firm-specific risk.
The BC and federal regulatory landscape for financial services is layered. BCFSA regulates insurance, mortgage brokers, credit unions, and real estate in BC. BCSC and the Canadian Securities Administrators regulate securities activity, with CIRO carrying operational requirements for dealers and advisers. OSFI supervises federally regulated financial institutions including banks and federally regulated insurance. FCAC oversees federally regulated consumer-protection obligations. FINTRAC enforces federal anti-money-laundering and record-keeping obligations under the PCMLTFA for reporting entities including MSBs, securities dealers, real estate, and certain insurers. Federal PIPEDA applies to personal information handling, with BC PIPA applying to provincial-jurisdiction activities. We implement and document the IT-side controls these frameworks expect.
Market hours, quarter-end, and commission-run cycles drive our change windows:
Market hours and client expectations do not wait. Our commitments:
Founded in 2020 by Alex Barari, a former PCI DSS Internal Security Assessor, Hexafusion is built around exactly the disciplines financial services examinations test. Access control, change management, audit logging, data residency, and incident response are core competencies, not add-ons. Our engineers are Microsoft, Cisco, and CompTIA certified, we procure hardware as a Dell authorized partner, and we are based at 250-997 Seymour St in downtown Vancouver, within the response windows published on this page for most Lower Mainland firms.
We work alongside platform vendors and firm compliance rather than around them. Application questions on Envestnet, Dataphile, Croesus, Finmo, or Applied Epic route to the platform. Our lane is the IT around those platforms: identity, privileged access, device fleet, conditional access, data residency, audit logging, secure client exchange, and the evidence packages a regulator examination or cyber-insurance renewal depends on.
We serve BC financial-services businesses of every size, from a solo mortgage broker or independent financial adviser through to multi-advisor investment offices, insurance brokerages, and small credit unions. Our baseline for encryption, MFA, PAM, audit logging, and Canadian data residency does not change with the size of the firm. Only the scope of the engagement does.
Do you understand BCFSA, BCSC, and CIRO expectations on IT?
Yes. We implement access controls, audit trails, retention, and incident-response documentation these regulators expect to see during an examination.
Do you support Envestnet, Dataphile, Croesus, and similar platforms?
Yes, at the workstation, network, and identity layers. Application administration stays with the platform or firm compliance team.
Do FINTRAC obligations apply to us?
FINTRAC reporting obligations apply to reporting entities under the PCMLTFA, including MSBs, securities dealers, real estate, and certain insurers. We implement the retention, secure storage, and retrieval workflows on the IT side.
Can you provide privileged access management for our firm?
Yes. Separated admin accounts, just-in-time privilege, MFA on every privileged session, and PAM tooling for service accounts.
How do you handle client data segregation between advisor books?
Role-based access, folder- and library-level permissions, conditional access scoped per advisor or team, and access logging. Ethical walls enforced at the system layer.
Do you work with Canadian data residency?
Yes. Canadian Azure and Microsoft 365 regions by default, US-routed services flagged for firm decision.
Cyber insurers, regulator examiners, and institutional counterparties all now expect financial services firms to produce clean evidence of MFA coverage, privileged access separation, backup immutability, EDR deployment, data residency, phishing training cadence, and incident-response documentation. Firms that cannot produce that evidence pay higher premiums, fail counterparty due diligence, or draw examination findings. We operate the environment to those standards and maintain the evidence as a normal output of the engagement rather than a quarterly scramble: backup test-restore logs, authentication audit exports, PAM session records, access reviews, tabletop notes, and OSFI-aligned incident-reporting runbooks for federally regulated firms.
Financial-services engagements usually include pieces from Managed IT Vancouver, Cybersecurity Vancouver, Cloud Services Vancouver, Backup & Disaster Recovery, and IT Supplier Vancouver.
Alongside financial services firms we support law firms, accounting firms, and real estate brokerages. The overlapping regulatory obligations (BCFSA, FINTRAC, BCSC) call for the same disciplined controls.
Reviewed by Alex Barari, Founder, former PCI DSS Internal Security Assessor (ISA).
We review your privileged access, client data segregation, audit logging, data residency, backup, and examination-evidence posture, then deliver a written report.
Book a financial-services IT assessment