Are any firms using application level encryption?

We are in the process of refactoring and cleaning up the FIX Session Layer standards documents for FIX4 and FIXT session layers. The use of application layer encryption was deprecated a number of years ago, being replaced by securing the transmission layer with SSL / TLS, etc.

Are there firms that are still using application layer encryption using the SecureDataLen(90) and SecureData(91) fields in the StandardHeader and the SignatureLength(93) and Signature(89) fields in the StandardTrailer?

Hello Jim,

MACD implemented the connection to the EMX Message System, a UK-based electronic
funds messaging platform some years ago. They used some special “extensions” to FIX, including encryption and signed headers. Maybe @georgemacdonald could give you some recent details.

Cheers, Jörg