Security, compliance & trust

Answered here. So it's never the reason a deal stalls

These are the questions that come up on every sales call in this category. Precise answers, not adjectives.

SOC 2 Type II

Independently audited controls

ISO 27001

Information security management

Encryption everywhere

In transit and at rest, no exceptions

Full audit trail

Every action, attributable and timestamped

*Certification badges shown for site-design purposes, confirm current audit status and report availability before this page goes live.

Data residency & hosting

Regional hosting, available when you need it

Some firms must keep data in a specific country or region. We arrange regional hosting on request, for each account, based on your needs. Tell us the jurisdiction and the rule that applies. We confirm what is possible and how long it takes.

Discuss regional hosting
Data residency configuration screen

Access control & audit logging

Every action, attributable to a person, a time, and a reason

Role-based access

Down to the fund and workflow level. Not just the account.

Full audit log

Who changed what, when, exportable for your own auditors.

SSO & MFA

Enforced at the account level, not opt-in per user.

Business continuity

Numbers, not adjectives

99.9%

Uptime target, all plans

< 15 min

Recovery Point Objective (RPO)

< 1 hr

Recovery Time Objective (RTO)

Illustrative targets. Committed figures are published on the Trust Center at go-live.

Regulatory coverage

Stated precisely, by geography

Regulatory coverage is confirmed per engagement, matched to the specific jurisdictions and reporting formats your firm answers to. Ask on a call for the list that covers your regulators.

Have a security questionnaire?

Talk to us directly, no need to wait for a sales cycle to get answers.