Skip to content

Security

Designed for sensitive investment information.

Investment material is confidential by nature. Our security model is built around controlled access, protected storage, recorded activity, isolated client data and human approval of decision-facing output.

A note on claims. The practices described on this page are design principles that guide how Pillarium Intelligence is built and operated. Where an implementation detail or independent certification is not confirmed, we describe it as a design principle rather than presenting it as a certified fact. We do not claim compliance certifications, audits or attestations that we have not obtained.

Principle 01

Access controls

Access is granted on a least-privilege basis. Roles determine what a user can view, edit, review and export within a workspace.

  • Role-based permissions across workspaces and deals
  • Separation between analyst, reviewer and administrator functions
  • Session controls and enforced sign-out

Principle 02

Encryption

Confidential material is protected in transit and at rest using established, industry-standard cryptographic practice.

  • Encrypted transport for all application traffic
  • Encryption at rest for stored documents and derived data
  • Managed key handling separated from application logic

Principle 03

Auditability

Activity that affects analysis or reporting is recorded so that decisions can be reconstructed after the fact.

  • Activity history for uploads, analysis runs and exports
  • Review and approval events attributed to a user
  • Last-updated visibility on findings and reports

Principle 04

Data isolation

Client material is kept logically separated so that documents and derived analysis remain confined to their own workspace.

  • Workspace-level separation of documents and analysis
  • Scoped access boundaries between engagements
  • No cross-client reuse of confidential content

Principle 05

Retention controls

Retention is treated as a client decision. Material can be removed when an engagement ends or a policy requires it.

  • Configurable retention periods per workspace
  • Deletion of documents and derived artefacts on request
  • Defined handling for exported material

Principle 06

Responsible AI and human approval

Automated analysis is a decision input, not a decision. Human review is required before output reaches a committee.

  • Evidence references attached to findings for verification
  • Confidence indicators on extracted and derived values
  • Explicit human approval before decision-facing output

Enterprise security enquiry

Reviewing us as a vendor?

We work with information-security, risk and compliance teams during evaluation. Request our current security documentation and we will respond with what can be substantiated.