1. Home
  2. Integrations
Integrations

What Marqib connects to, and what each connection does.

Data comes in through connectors, signed webhooks or files. Case files, alerts, the audit log and draft reports go out. Each tile shows the status of the connection today.

Status:AvailableBeta — validated with your account during the pilotPlanned

How the connections work

  • How data gets in.Connectors pull from the trading platform and the back office on a schedule. KYC, payment and crypto tools push signed webhooks. Everything else arrives as files, uploaded or collected nightly from the firm's storage.
  • What comes out.Case files with evidence, alerts in the tools the team already uses, the audit log for the security team's SIEM, and draft reports for goAML and MASAK.
  • Read-only.Connectors only read, with a login the firm issues for the purpose. Marqib does not place trades, move money, change KYC records or release anything in another system.
  • Credentials stored encrypted.Passwords, API keys, webhook secrets and storage keys are encrypted with AES-256-GCM and never shown again, logged or written to the audit log. Each settings change, test and sync is recorded in the audit log.
  • Self-hosted: data stays in your environment.In a self-hosted installation the connections run from the firm's environment to its own systems and providers. Nothing passes through a Marqib service.

Trading platforms

MetaTrader 5

Web API connector with a manager login: clients, deals, deposits and withdrawals, bonus and credit operations and order history, pulled on a schedule.

Beta — validated with your account during the pilot

cTrader

WebServices API connector for accounts and closed positions. Balance and bonus history come from cTrader exports, imported on the Data page.

Beta — validated with your account during the pilot

Data delivery

File drop

Nightly exports pulled from S3-compatible storage (AWS S3, Cloudflare R2, MinIO, Wasabi), Azure Blob Storage with a SAS URL, or HTTPS. Read-only credentials are enough.

Available

CSV upload

The same file layouts, uploaded by hand on the Data page. Each file is validated before anything is written.

Available

Real-time decision API

Send a deposit or withdrawal before it is processed. The answer is allow, review or hold, with reasons; review and hold open a case.

Available

Back office and payments

Praxis Cashier

Signed payment notifications plus transaction look-up: payer name, masked card number and withdrawal requests still pending, so a hold can be placed before payout.

Beta — validated with your account during the pilot

B2Core

API pull: clients with their KYC level, and deposits and withdrawals, including pending ones.

Beta — validated with your account during the pilot

KYC and screening

Sumsub

Signed webhooks, with API pull by client. KYC decisions and screening results feed the risk score; a confirmed sanctions hit opens a case.

Beta — validated with your account during the pilot

ComplyAdvantage Mesh

Signed webhooks; alerts and risks are pulled through the API. Sanctions, PEP and adverse-media results feed the risk score and cases.

Beta — validated with your account during the pilot

Veriff

Signed decision and watchlist-screening webhooks. Verification outcomes and possible matches feed the risk score.

Beta — validated with your account during the pilot

LSEG World-Check One

Pull only, read with the firm's own World-Check licence; the data stays in its tenant. Sanctions, PEP and adverse-media results and the firm's resolutions feed the risk score and cases.

Beta — validated with your account during the pilot

Onfido

Signed webhooks; the result is read with the API token. Identity verification and watchlist reports feed the risk score.

Beta — validated with your account during the pilot

Generic signed webhook

For any other provider or an in-house KYC system: results as HMAC-signed JSON in a documented format.

Available

Sanctions lists

UN, OFAC, EU and UK lists fetched from the publishers and versioned by SHA-256. The UAE Local Terrorist List and MASAK lists are loaded by upload.

Available

Crypto

KYTGate

Signed webhooks and a read-only API. Blocked wallets and transfers open a Crypto wallet exposure case. Marqib never screens or releases funds in KYTGate.

Beta — validated with your account during the pilot

Chainalysis KYT

Alerts read with the firm's API key; there is no webhook. Severe or high alerts, or alerts an analyst flagged, open a Crypto wallet exposure case.

Beta — validated with your account during the pilot

Elliptic

Signed webhooks (Ed25519) for wallet and transaction screenings, with an optional read. Sanctions exposure or a high risk score opens a Crypto wallet exposure case.

Beta — validated with your account during the pilot

TRM Labs

Through the generic webhook today.

Alerts and security operations

Microsoft Teams

New cases, holds and decisions posted to a channel with a link to the case. Identifiers only: no names, amounts or account details leave Marqib.

Available

Slack

The same events and the same rule: identifiers only, with a link to the case.

Available

Signed webhooks

Case events to the firm's own systems, HMAC-signed, with a delivery id for de-duplication. Identifiers only.

Available

Splunk HTTP Event Collector

The audit log, entry by entry with its hash chain, pushed to a Splunk the firm controls.

Available

Audit-log API

For SIEMs that poll, such as Microsoft Sentinel, QRadar or Elastic: audit entries read page by page with an API key limited to that scope.

Available

Microsoft Entra ID · Google · Okta

Single sign-on through OpenID Connect; roles can come from the identity provider. SAML is not supported.

Available

Regulatory output

goAML XML draft

STR draft for the UAE FIU, checked before export. Indicator and lookup code lists are to be confirmed with the FIU.

Beta — validated with your account during the pilot

MASAK ŞİB draft

Suspicious transaction report draft for Türkiye, which the compliance officer checks and submits in MASAK's own system. Suspicion-type codes are to be confirmed.

Beta — validated with your account during the pilot

Evidence pack

Printable case file with its own SHA-256, so the file the regulator sees is the one that was approved.

Available

Planned

Not built yet. No dates are promised.

SFTP

File drop from an SFTP server.

Planned

MT4

A direct connector. MT4 data works through CSV exports today.

Planned

cTrader Manager API

Balance, bonus and order history straight from cTrader. Needs access granted by Spotware.

Planned

uqudo

UAE identity verification results. Until then, through the generic webhook.

Planned

Open banking: Lean, Tarabut

Account and payment data from Gulf open-banking providers.

Planned

Product names and trademarks belong to their owners. Their use here only describes compatibility; it does not imply partnership, endorsement or certification.

Connectors marked beta are built against the vendor's published documentation and validated with the customer's own account during the pilot.

Which of these do you use?

Name your trading platform, back office and KYC provider in the pilot request. Beta connectors are validated with your account during the pilot.