Security
Designed for sensitive investment information.
Investment material is confidential by nature. Our security model is built around controlled access, protected storage, recorded activity, isolated client data and human approval of decision-facing output.
Principle 01
Access controls
Access is granted on a least-privilege basis. Roles determine what a user can view, edit, review and export within a workspace.
- Role-based permissions across workspaces and deals
- Separation between analyst, reviewer and administrator functions
- Session controls and enforced sign-out
Principle 02
Encryption
Confidential material is protected in transit and at rest using established, industry-standard cryptographic practice.
- Encrypted transport for all application traffic
- Encryption at rest for stored documents and derived data
- Managed key handling separated from application logic
Principle 03
Auditability
Activity that affects analysis or reporting is recorded so that decisions can be reconstructed after the fact.
- Activity history for uploads, analysis runs and exports
- Review and approval events attributed to a user
- Last-updated visibility on findings and reports
Principle 04
Data isolation
Client material is kept logically separated so that documents and derived analysis remain confined to their own workspace.
- Workspace-level separation of documents and analysis
- Scoped access boundaries between engagements
- No cross-client reuse of confidential content
Principle 05
Retention controls
Retention is treated as a client decision. Material can be removed when an engagement ends or a policy requires it.
- Configurable retention periods per workspace
- Deletion of documents and derived artefacts on request
- Defined handling for exported material
Principle 06
Responsible AI and human approval
Automated analysis is a decision input, not a decision. Human review is required before output reaches a committee.
- Evidence references attached to findings for verification
- Confidence indicators on extracted and derived values
- Explicit human approval before decision-facing output
Enterprise security enquiry
Reviewing us as a vendor?
We work with information-security, risk and compliance teams during evaluation. Request our current security documentation and we will respond with what can be substantiated.