The challenge
TradeLocker gives traders one connected home to execute, manage risk, and stay in flow, and gives its broker and prop firm partners the infrastructure to run that experience. Nearly the whole team works from its Zagreb office, and the company's infrastructure runs on AWS, reachable only through the in-office network.
For most of TradeLocker's life, that perimeter was governed by trust. The team was made up of technical, security-aware people, and everyone maintained security on their own. For most of TradeLocker's life, that perimeter was governed by trust.
"We were a startup company focusing primarily on delivering a good product. The security came from trusting people. But as the company expands, it gets hard to manage that many devices by handing someone a piece of paper and saying, these are the rules we would love you to abide by."
Bojan DunkicSystem Administrator, Tradelocker
As the company grew, Bojan found that relying on people to manage their devices, with no dedicated security hire, was leading to downstream issues. TradeLocker's business partners got bigger and expected a demonstrably mature, security-aware company. This led to TradeLocker taking the potential security issues more seriously.
So TradeLocker hired its first dedicated security role: Head of Security and Infrastructure. When Alojz stepped into it, he found what informal security usually leaves behind: misconfigurations, no enforced password policy, laptops without encryption, and no way to see any of it in one place.
His first decision was immediate. TradeLocker needed device management.
"Everybody thinks the threat will come from outside, that somebody will get into the office and put a cable in the network. But your laptop is the most exposed device to the internet. AWS was already secure, and access to it can only happen from our network. And laptops are on our network. So the main thing for me was to secure the laptops."
Alojz KvočićHead of Security and Infrastructure, Tradelocker
The solution
Three requirements, one platform
From the start of the evaluation, Alojz knew he wasn't shopping for an MDM alone.
When TradeLocker went looking, the requirement was MDM, EDR, and a vulnerability scanner together, because the whole point was to utilize a unified platform for all three. Bojan, TradeLocker's system administrator, had administered device management platforms for over a decade at previous companies, always inheriting someone else's choice. This time the decision was his and Alojz's to make, and they tried five or six tools before landing on Iru.
"Iru is the right fit for TradeLocker because we wanted simplicity. From my experience, it has the best and simplest interface to work with."
Alojz KvočićHead of Security and Infrastructure, Tradelocker
Some platforms offered longer feature lists on paper, but they were slow and unfriendly to work with. What he wanted was everything the team would actually use, in an interface that stays out of the way, with a support team that can respond quickly
"There are many brands in the space, but none of them had the same approach as Iru has with customer support. I can send in a ticket, it gets looked at by a real person, assessed properly, and then I can have a conversation with that person and explain what I'm trying to do. That was extremely important to me and to TradeLocker."
Bojan DunkicSystem Administrator, Tradelocker
A ISO 27001 baseline, tuned to how the team actually works
Rather than creating every configuration policy from scratch, Alojz started from one of Iru's recommended Blueprint templates and modified components to TradeLocker's needs. He and Bojan tested the Blueprint on their own laptops for a month before rolling out team by team.
The rollout philosophy mattered; it meant friction for their employees. Employees were concerned about losing access to tools and permissions. Instead, the pair tuned the rules wherever a restriction wasn't solving a real problem: they kept AirDrop available even though the stock blueprint blocked it, widened the Chrome update window to a week after enforced restarts caught people mid-work, and trimmed the onboarding pop-ups down to a clean, branded minimum.
"We don't use Iru as a brick wall. We use it as an enablement tool. People know that even if something is malicious, there's something backing them up that will save them, and the company. It's easier for them to do their daily work."
Bojan DunkicSystem Administrator, Tradelocker
Putting detection to the test
With EDR and Vulnerability Management live, Alojz was ready to attack his own fleet and test Iru's capabilities. He found an old offline installer of Chrome and installed it on a test machine.
"Immediately the notifications came in. We have Iru connected to our Slack, with a channel for critical vulnerabilities, and when we installed the old Chrome, there they were. It's really quick at detecting. It's almost real time."
Alojz KvočićHead of Security and Infrastructure, Tradelocker
He went a step further and downloaded cracked software from a shady website. The moment he unpacked it, Iru's EDR flagged it.
Day to day, the same tools keep TradeLocker’s whole software stack current, from operating software to custom applications. TradeLocker's developers use a long tail of specialized tools, and Iru monitors and updates all of it. When something isn't in Iru's app catalog yet, the team files a request to add it.
Working toward ISO 27001 with Iru compliance
Standing up device management was phase one. The next phase started earlier than expected, because, during the evaluation, Bojan discovered something he didn't know existed.
"When I was looking at MDMs, I didn't know Iru had a compliance platform. We're early adopters, and it's been amazing. It holds your hand and tells you, these are the things you have to have in place. The compliance and the endpoint management platform just go hand in hand."
Bojan DunkicSystem Administrator, Tradelocker
TradeLocker set ISO 27001 as its baseline in the platform and has been connecting its systems as sources: AWS, Slack, Google Workspace, and Iru MDM itself. This accounts for half of TradeLocker's systems so far. Iru’s Compliance Automation scans each connected source's actual settings against TradeLocker's policies, and gathers the evidence on its own instead of someone typing findings into a spreadsheet system by system. AI does the connective work, thereby eliminating manual processes.
"We're all humans. Nobody wants to read 500 pages of compliance reports. I've been part of a couple of ISO certifications, and this has been the easiest way of gathering information that I've seen in my ten-plus years of experience."
Bojan DunkicSystem Administrator, Tradelocker
Iru’s Compliance automation also helps with security questionnaires.
"We're all humans. Nobody wants to read 500 pages of compliance reports. I've been part of a couple of ISO certifications, and this has been the easiest way of gathering information that I've seen in my ten-plus years of experience."
Bojan DunkicSystem Administrator, Tradelocker
"We have partners asking us questions, and in the Trust Center, the AI answers them automatically without us having to manually write out a hundred answers in an Excel sheet. It saves us massive amounts of time and keeps our sales and partner pipeline moving smoothly."
Alojz KvočićHead of Security and Infrastructure, Tradelocker
AI that does real work
The AI thread runs through more than compliance. Iru's AI has become part of how the team operates the platform day to day. If it surfaces that most of the fleet is already running an app and adds it to a Blueprint and self-service in one click, and during setup it answered configuration questions faster than digging through documentation.
"You can use it for daily tasks and ask it anything. It's not just, we have AI so we can say we have AI. It's really working."
Alojz KvočićHead of Security and Infrastructure, Tradelocker
Results
In about three months from Alojz's first day, TradeLocker went from no security function to an enforced, visible baseline across its fleet: encryption on, password policy applied, every device patching automatically, and critical vulnerabilities surfacing in Slack in near real time.
"From the demo phase to production, it was a very quick transfer. We had already tested and set up everything in the demo phase, and we were on weekly meetings with the Iru team throughout. When we went to production, it was just done."
Alojz KvočićHead of Security and Infrastructure, Tradelocker
For Bojan, the conclusion is simple.
"There are a lot of good tools out there, but Iru is the only tool I've found that checks all of the boxes for TradeLocker."
Bojan DunkicSystem Administrator, Tradelocker
Looking ahead
The compliance work is the next chapter, and it's deliberately ahead of schedule. TradeLocker hasn't set a certification date for ISO 27001; instead, the team is operating as if the audit were already booked, connecting more sources to the compliance module and letting the evidence accumulate, so that when preparation formally begins, most of it will already be done. Alojz suspects there's plenty of room left to grow into.
"I think we've only scratched the surface, maybe five percent of what's possible in Iru for compliance."
Alojz KvočićHead of Security and Infrastructure, Tradelocker
About TradeLocker
TradeLocker is a trading platform built to be a nerve center for trading: one unified platform where traders have the charting, execution, and tools they need in a single place. Designed around the requirements of millions of traders, TradeLocker partners with brokers around the world, with its team based primarily in Zagreb, Croatia.