| Message retention & archivingDORA · MiFID II · HIPAA | Bloomberg Vault: fully compliant archiving | Built-in compliance retention and eDiscovery | ML-DSA-signed messages anchored on BSV: permanent, timestamped |
| Records independent of operator controlDORA Art. 11 · MiFID II Art. 25 | Bloomberg controls the infrastructure, so records are under vendor control | Symphony controls the infrastructure, the same structural dependency | PoW anchoring: no operator, including Bastion, can amend the record |
| Cryptographic sender non-repudiationMiFID II Art. 25 · legal proceedings | Platform-level attribution: the server asserts identity, not a user-held key | Platform-level signatures, not user-key cryptographic proof | ML-DSA-87: the sender's private key signed the message, verifiable by any party |
| End-to-end confidentiality, no server-side plaintextHIPAA § 164.312 · legal privilege | Bloomberg has content access, required for compliance archiving | E2EE option exists, but compliance key escrow means a third party holds keys | AES-256-GCM with ratchet-derived keys: no server ever holds plaintext |
| Compliance attestation without content disclosurecross-institutional regulated markets | Compliance proof requires content disclosure to Bloomberg | Compliance proof requires content disclosure to Symphony | Phase 3 — zk-STARK delivery receipts: prove delivery without revealing content |
| Quantum-resistant encryption10-year confidentiality horizon | Classical encryption, vulnerable to harvest-now-decrypt-later | Classical encryption, same exposure | ML-KEM-1024 hybrid: quantum-resistant from day one |