Security and data
What we store today, how access works, and what has to be in place before we accept any of your data.
What we store today
Public articles and filings, the signals derived from them, provenance receipts, operational logs, and the email addresses of people who subscribe to the brief. Subscriber confirmation tokens are treated as secrets.
When you request access, we store the name, work email, firm, role and message you submit, together with the submission time and limited abuse-prevention metadata. We use it only to review and respond to the request.
Logs must not contain API keys, confirmation tokens, email bodies or holdings. Anyone can unsubscribe; a deletion request removes the subscriber record and any delivery-system contact record. Backups expire on a fixed schedule and are not edited selectively.
How access works
- Accounts are created by invitation. There is no self-service sign-up.
- Each product runs on its own hostname over TLS, with its own sign-in. Portfolio also restricts sign-in attempts and accepts connections only through its dedicated hostname.
- Production data is reachable only through the server's cloud instance role, a managed secrets store and a dedicated service account.
- Records that matter are append-only and hash-chained. Corrections are new entries that point to what they correct.
- Portfolio runs with no broker connection, no stored broker password, no browser automation and no order, transfer, withdrawal or sell interface. No language model takes part in its decisions.
Before we accept your data
Holdings, portfolios and your own research are out of scope until a design partner asks for them and the following are approved:
- A threat model for your data path
- An encryption design, in transit and at rest
- Separation of your data from every other customer's
- A deletion workflow and retention rules agreed with you
- An audit log of every access, including ours
- A privacy notice and data-processing terms
Your data is never used to train shared models without a separate written agreement, and never sent to a model provider you haven't approved.
If your security team has a questionnaire, send it with your access request and we'll answer it before any pilot starts.