Security

Security isn't a feature. It's the foundation.

Your fund data is your competitive advantage. We treat it that way. Per-fund isolation, zero-trust architecture, and LP-grade audit trails are built into every layer.

Per-Fund Data Isolation

Each fund's data lives in its own encrypted namespace. No cross-fund data leakage. No shared keys. Complete logical and physical separation.

No Training on Your Data

Your portfolio data is never used to train AI models. Not ours. Not third-party. Your fund performance, LP details, and deal terms stay yours.

LP-Grade Audit Trail

Every action logged, every access tracked, every change attributed. Full audit history exportable for LP due diligence and compliance reviews.

SOC 2 Type II (Planned)

Enterprise security certification in progress. Our controls are designed to meet SOC 2 requirements across security, availability, and confidentiality.

Encryption at Rest & Transit

AES-256 encryption at rest. TLS 1.3 in transit. Keys rotated automatically. No unencrypted data ever touches disk or network.

Role-Based Access

GP, LP, analyst, admin. Each role sees exactly what they should. Granular permissions down to the document level. SSO and MFA included on all plans.

Compliance

Built for institutional requirements.

Derek is designed to meet the security and compliance standards expected by institutional LPs.

SOC 2 Type II*
AES-256
TLS 1.3
SSO/SAML
MFA

* SOC 2 Type II certification in progress

Data Handling

Your data. Your control.

Data Residency

Choose where your data lives. US, EU, or single-tenant deployment for Enterprise customers. All infrastructure runs on SOC 2 certified cloud providers.

Data Export

Export all your data at any time in standard formats. Full fund data, LP records, documents, and audit logs. No lock-in. No export fees.

Data Retention

You control retention periods. Set custom policies per fund or document type. Automated deletion with verification. Compliant with GDPR and CCPA.

Incident Response

24-hour breach notification commitment. Dedicated security team with documented incident response procedures. Annual penetration testing by third-party auditors.

Questions about security?

Our security team is available to discuss your specific requirements and provide detailed documentation for LP due diligence.