Security isn't a feature. It's the foundation.
Your fund data is your competitive advantage. We treat it that way. Per-fund isolation, zero-trust architecture, and LP-grade audit trails are built into every layer.
Each fund's data lives in its own encrypted namespace. No cross-fund data leakage. No shared keys. Complete logical and physical separation.
Your portfolio data is never used to train AI models. Not ours. Not third-party. Your fund performance, LP details, and deal terms stay yours.
Every action logged, every access tracked, every change attributed. Full audit history exportable for LP due diligence and compliance reviews.
AES-256 encryption at rest. TLS 1.3 in transit. Keys rotated automatically. No unencrypted data ever touches disk or network.
GP, LP, analyst, admin — each role sees exactly what it should. Granular permissions down to the document level. SSO and MFA included.
Built for institutional requirements.
Derek is designed to meet the security and compliance standards expected by institutional LPs.
Your data. Your control.
Choose where your data lives — US, EU, or single-tenant deployment for Enterprise. All infrastructure runs on SOC 2 certified cloud providers.
Export everything at any time in standard formats — fund data, LP records, documents, audit logs. No lock-in. No export fees.
You control retention periods — custom policies per fund or document type, automated deletion with verification. GDPR and CCPA compliant.
24-hour breach notification commitment, a dedicated security team with documented procedures, and annual third-party penetration testing.
Questions about security?
Our security team is available to discuss your specific requirements and provide detailed documentation for LP due diligence.
Contact the security team