- Home
- Integrations
What Marqib connects to, and what each connection does.
Data comes in through connectors, signed webhooks or files. Case files, alerts, the audit log and draft reports go out. Each tile shows the status of the connection today.
How the connections work
- How data gets in.Connectors pull from the trading platform and the back office on a schedule. KYC, payment and crypto tools push signed webhooks. Everything else arrives as files, uploaded or collected nightly from the firm's storage.
- What comes out.Case files with evidence, alerts in the tools the team already uses, the audit log for the security team's SIEM, and draft reports for goAML and MASAK.
- Read-only.Connectors only read, with a login the firm issues for the purpose. Marqib does not place trades, move money, change KYC records or release anything in another system.
- Credentials stored encrypted.Passwords, API keys, webhook secrets and storage keys are encrypted with AES-256-GCM and never shown again, logged or written to the audit log. Each settings change, test and sync is recorded in the audit log.
- Self-hosted: data stays in your environment.In a self-hosted installation the connections run from the firm's environment to its own systems and providers. Nothing passes through a Marqib service.
Trading platforms
MetaTrader 5
Web API connector with a manager login: clients, deals, deposits and withdrawals, bonus and credit operations and order history, pulled on a schedule.
Beta — validated with your account during the pilotcTrader
WebServices API connector for accounts and closed positions. Balance and bonus history come from cTrader exports, imported on the Data page.
Beta — validated with your account during the pilotData delivery
File drop
Nightly exports pulled from S3-compatible storage (AWS S3, Cloudflare R2, MinIO, Wasabi), Azure Blob Storage with a SAS URL, or HTTPS. Read-only credentials are enough.
AvailableCSV upload
The same file layouts, uploaded by hand on the Data page. Each file is validated before anything is written.
AvailableReal-time decision API
Send a deposit or withdrawal before it is processed. The answer is allow, review or hold, with reasons; review and hold open a case.
AvailableBack office and payments
Praxis Cashier
Signed payment notifications plus transaction look-up: payer name, masked card number and withdrawal requests still pending, so a hold can be placed before payout.
Beta — validated with your account during the pilotB2Core
API pull: clients with their KYC level, and deposits and withdrawals, including pending ones.
Beta — validated with your account during the pilotKYC and screening
Sumsub
Signed webhooks, with API pull by client. KYC decisions and screening results feed the risk score; a confirmed sanctions hit opens a case.
Beta — validated with your account during the pilotComplyAdvantage Mesh
Signed webhooks; alerts and risks are pulled through the API. Sanctions, PEP and adverse-media results feed the risk score and cases.
Beta — validated with your account during the pilotVeriff
Signed decision and watchlist-screening webhooks. Verification outcomes and possible matches feed the risk score.
Beta — validated with your account during the pilotLSEG World-Check One
Pull only, read with the firm's own World-Check licence; the data stays in its tenant. Sanctions, PEP and adverse-media results and the firm's resolutions feed the risk score and cases.
Beta — validated with your account during the pilotOnfido
Signed webhooks; the result is read with the API token. Identity verification and watchlist reports feed the risk score.
Beta — validated with your account during the pilotGeneric signed webhook
For any other provider or an in-house KYC system: results as HMAC-signed JSON in a documented format.
AvailableSanctions lists
UN, OFAC, EU and UK lists fetched from the publishers and versioned by SHA-256. The UAE Local Terrorist List and MASAK lists are loaded by upload.
AvailableCrypto
KYTGate
Signed webhooks and a read-only API. Blocked wallets and transfers open a Crypto wallet exposure case. Marqib never screens or releases funds in KYTGate.
Beta — validated with your account during the pilotChainalysis KYT
Alerts read with the firm's API key; there is no webhook. Severe or high alerts, or alerts an analyst flagged, open a Crypto wallet exposure case.
Beta — validated with your account during the pilotElliptic
Signed webhooks (Ed25519) for wallet and transaction screenings, with an optional read. Sanctions exposure or a high risk score opens a Crypto wallet exposure case.
Beta — validated with your account during the pilotTRM Labs
Through the generic webhook today.
Alerts and security operations
Microsoft Teams
New cases, holds and decisions posted to a channel with a link to the case. Identifiers only: no names, amounts or account details leave Marqib.
AvailableSlack
The same events and the same rule: identifiers only, with a link to the case.
AvailableSigned webhooks
Case events to the firm's own systems, HMAC-signed, with a delivery id for de-duplication. Identifiers only.
AvailableSplunk HTTP Event Collector
The audit log, entry by entry with its hash chain, pushed to a Splunk the firm controls.
AvailableAudit-log API
For SIEMs that poll, such as Microsoft Sentinel, QRadar or Elastic: audit entries read page by page with an API key limited to that scope.
AvailableMicrosoft Entra ID · Google · Okta
Single sign-on through OpenID Connect; roles can come from the identity provider. SAML is not supported.
AvailableRegulatory output
goAML XML draft
STR draft for the UAE FIU, checked before export. Indicator and lookup code lists are to be confirmed with the FIU.
Beta — validated with your account during the pilotMASAK ŞİB draft
Suspicious transaction report draft for Türkiye, which the compliance officer checks and submits in MASAK's own system. Suspicion-type codes are to be confirmed.
Beta — validated with your account during the pilotEvidence pack
Printable case file with its own SHA-256, so the file the regulator sees is the one that was approved.
AvailablePlanned
Not built yet. No dates are promised.
SFTP
File drop from an SFTP server.
PlannedMT4
A direct connector. MT4 data works through CSV exports today.
PlannedcTrader Manager API
Balance, bonus and order history straight from cTrader. Needs access granted by Spotware.
Planneduqudo
UAE identity verification results. Until then, through the generic webhook.
PlannedOpen banking: Lean, Tarabut
Account and payment data from Gulf open-banking providers.
PlannedProduct names and trademarks belong to their owners. Their use here only describes compatibility; it does not imply partnership, endorsement or certification.
Connectors marked beta are built against the vendor's published documentation and validated with the customer's own account during the pilot.
Which of these do you use?
Name your trading platform, back office and KYC provider in the pilot request. Beta connectors are validated with your account during the pilot.