Security & Compliance

Built for regulated wealth management.

Enterprise-grade infrastructure designed for the security and compliance requirements of family offices worldwide.

Two-factor authentication

TOTP-based MFA with backup codes for all users. Hardware security key support available.

Encrypted integrations

AES-CBC encryption for all OAuth tokens and API credentials. Zero plaintext storage.

Complete audit logs

Every action tracked with user, timestamp, and IP. Export to CSV for compliance reporting.

Role-based access

Granular permissions at organization, family, and document level. Custom role definitions.

Data provenance

Every extracted field traces to its source document. Full lineage for compliance.

Multi-jurisdiction

Designed for SEC, FCA, MAS, and FINMA regulatory frameworks. Configurable retention policies.

Infrastructure

Security by design.

Every layer of our infrastructure is built with security and privacy as the foundation.

Row-level security

Enforced at the database layer for complete data isolation between families and organizations.

Zero-trust architecture

Every request authenticated and authorized. No implicit trust between services.

No AI training on your data

Your documents and data are never used to train our AI models. Your data stays yours.

Isolated infrastructure

Deployed on isolated infrastructure with SOC 2 Type II compliance. Regular penetration testing.

Compliance

Certified and audited.

SOC 2 Type IIAES-256 EncryptionGDPR CompliantZero-trust ArchitectureISO 27001CCPA Compliant

Questions about security?

Our team is happy to discuss our security practices and compliance certifications in detail.

Contact Us