Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Secrets and API keys are stored in a managed vault and rotated on a schedule.
Stewardship data — draft voting intentions, engagement notes, controversy assessments — is some of the most sensitive information an asset manager holds. engage insights is built so it stays private, provable and entirely yours.
We treat your data as your property, full stop. It is never used to train AI models, never shared with third parties, and never sold. Our AI features operate on your tenant's data only, and every recommendation is cited back to its source. When your contract ends, we export your data and delete it on a defined schedule.
The same controls institutional IT and risk teams expect from a critical financial system, applied to every tenant from day one.
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Secrets and API keys are stored in a managed vault and rotated on a schedule.
SAML / OIDC single sign-on, role-based access control and least-privilege permissions. Provision and de-provision users through your own identity provider.
Every action is logged with a user, timestamp and before/after state. Every AI recommendation is explainable and cited — no black boxes in your compliance record.
Hosted on hardened cloud infrastructure with EU and US regions available. Choose where your tenant's data lives to meet your residency requirements.
Data residency detailsGDPR and CCPA ready, with a Data Processing Agreement available on request. Our controls are designed against recognised frameworks and reviewed as we scale.
Request our DPAAutomated, encrypted backups with point-in-time recovery, redundant infrastructure and monitored uptime — so your reporting cycle never stalls on us.
Found a vulnerability? We want to hear from you. Report security concerns to our team and we'll acknowledge quickly and work with you on a coordinated fix. We do not pursue good-faith researchers who follow responsible-disclosure practices.
This page describes our security approach for general information and is not a warranty or part of any contract. Specific commitments, sub-processors and certifications are set out in your service agreement and Data Processing Agreement. For data-location specifics, see our data residency page; for processing terms, our DPA.
We'll walk your IT, risk and compliance teams through our controls, hosting and data-handling — and answer whatever your review process needs.