Security & Compliance

Enterprise-grade security.
Zero-knowledge architecture.

We handle the most sensitive deal data in private equity. Security isn't a featureβ€”it's our foundation.

πŸ”

End-to-End Encryption

AES-256 encryption at rest, TLS 1.3 in transit. Zero-knowledge architecture for sensitive data.

πŸ›‘οΈ

Multi-Tenant Isolation

Row-level security in PostgreSQL ensures complete data isolation between clients.

πŸ”‘

Kill Switch

One-click data deletion with cryptographic proof. Your data, your control.

πŸ“‹

SOC 2 Type II

Certification in progress (Q4 2026). Independent audit of security controls.

🌍

GDPR & CCPA Compliant

Full compliance with global privacy regulations. EU data residency available.

πŸ‘€

No Login Required for Upload

Secure dropbox links reduce credential risk. Optional MFA for platform access.

Documentation

Transparent by design.

All security documentation is publicly available. No NDA required to review our architecture.

Security Whitepaper

12 pages

Complete overview of our security architecture, encryption standards, and compliance framework.

Updated May 2026Download PDF β†’

SOC 2 Type II Readiness

8 pages

Current certification status, audit timeline, and compliance controls.

Updated May 2026Download PDF β†’

Data Retention & Deletion Policy

6 pages

How we handle your data lifecycle, retention periods, and secure deletion procedures.

Updated May 2026Download PDF β†’

GDPR & CCPA Compliance

10 pages

How we comply with global privacy regulations and protect customer data rights.

Updated May 2026Download PDF β†’
Certifications & Compliance

Industry-standard compliance.

πŸ”’

SOC 2 Type II

In Progress

Independent audit scheduled for Q4 2026. All controls implemented and operational.

🌍

GDPR Compliant

Certified

Full GDPR compliance. EU data residency available. Right to deletion, portability, and access.

πŸ“‹

CCPA Compliant

Certified

California Consumer Privacy Act compliance. Full transparency on data collection and usage.

πŸ—οΈ

ISO 27001

2027 Roadmap

International security standard planned for 2027 certification cycle.

FAQ

Security questions answered.

Where is data stored?

Primary storage: AWS US-East (N. Virginia). EU data residency available for GDPR requirements. All data encrypted at rest using AES-256.

Who can access my data?

Only authorized users with valid access tokens. Our engineering team has zero-knowledge access (encrypted data appears as ciphertext). SOC 2 audit trail logs all access attempts.

How long do you retain data?

Default: 90 days after report delivery. Configurable: 30-365 days based on your needs. You can delete all data instantly via kill switch at any time.

Do you sign NDAs?

Yes. Mutual NDAs are standard for all engagements. We can also sign your MSA/DPA if required by your procurement process.

What about AI model training?

Your data is NEVER used for AI model training. We use Anthropic Claude and OpenAI GPT with zero-retention APIs (data deleted after processing). Your competitive intelligence stays yours.

How do I delete my data?

Click "Delete All Data" in your dropbox settings. Cryptographic deletion certificate issued within 24 hours. Physical deletion from backups within 30 days (industry standard).

Questions about security?

Our security team is available to answer technical questions and review custom requirements.