Enterprise-Grade Security for Institutional Data
Built for the security and compliance requirements of pension funds, endowments, sovereign wealth funds, and fiduciaries managing sensitive investment data.
Data Security
Encryption at Rest & In Transit
All data encrypted in transit with TLS. Application-level encryption (Fernet) for stored third-party credentials. Database encryption managed at the cloud platform level. No unencrypted data leaves the platform.
Organization-Scoped Data Isolation
Each organization's data is isolated via organization-scoped row security across all shared tables. No co-mingled query results, no cross-tenant data access. Dedicated single-tenant deployment available on Enterprise.
Role-Based Access Control
Granular permissions across admin, manager, analyst, viewer, and consultant roles. Audit logging tracks every login, data access, and configuration change.
Compliance & Standards
Meeting the regulatory and reporting standards institutional investors require.
SOC 2 Type II
Targeted 2027Targeting SOC 2 Type II audit in 2027 covering security, availability, and confidentiality trust service criteria. Readiness assessment scheduled for Q3-Q4 2026 with audit window opening once remediation completes. Design-partner engagements can compress the timeline based on procurement requirements.
GIPS 2020
AlignedPerformance metrics (SI-IRR, PIC, DPI, RVPI, TVPI, PME) computed per GIPS 2020 definitions. Formal GIPS firm-level certification is not yet claimed.
ILPA Standards
AlignedILPA 2025 reporting template support with automated validation and reconciliation to $1 tolerance on four signed-convention formulas. Ongoing formula expansion per the ILPA Reconciliation Enhancement Backlog.
ERISA
SupportedPlan asset threshold monitoring (25% rule), prohibited transaction screening, and VCOC qualification tracking for fiduciary compliance.
Privacy & Data Handling
No Data Sharing
Your portfolio data is never shared with third parties, used for training AI models, or sold. Your data belongs to you.
Data Export & Portability
Export your complete dataset at any time in standard formats (Excel, PDF, CSV). No lock-in, no export fees.
Confidentiality Agreement
Every platform user must accept a comprehensive confidentiality agreement before accessing any data. Acceptance is audited with timestamps and IP logging.
Infrastructure
Cloud Hosting
Cloud infrastructure with automated deployments, health monitoring, and geographic redundancy.
Managed Backups
Platform-managed database backups with regular verification. Point-in-time-recovery capability is available on Enterprise deployments.
Production Monitoring
Proactive uptime monitoring across critical endpoints with automated alerting and incident response procedures. Contractual uptime SLAs available on Enterprise.
Questions about security or compliance?
Our team is happy to discuss security architecture, compliance requirements, and data handling policies.