Security & trust

    Enterprise-grade security for firms handling sensitive pre-decisional data.

    Stewardship data — draft voting intentions, engagement notes, controversy assessments — is some of the most sensitive information an asset manager holds. engage insights is built so it stays private, provable and entirely yours.

    Your data stays yours.

    We treat your data as your property, full stop. It is never used to train AI models, never shared with third parties, and never sold. Our AI features operate on your tenant's data only, and every recommendation is cited back to its source. When your contract ends, we export your data and delete it on a defined schedule.

    How we protect it

    Security controls, built in — not bolted on.

    The same controls institutional IT and risk teams expect from a critical financial system, applied to every tenant from day one.

    Encryption everywhere

    Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Secrets and API keys are stored in a managed vault and rotated on a schedule.

    Access controls & SSO

    SAML / OIDC single sign-on, role-based access control and least-privilege permissions. Provision and de-provision users through your own identity provider.

    Full audit trail & explainable AI

    Every action is logged with a user, timestamp and before/after state. Every AI recommendation is explainable and cited — no black boxes in your compliance record.

    Hosting & data residency

    Hosted on hardened cloud infrastructure with EU and US regions available. Choose where your tenant's data lives to meet your residency requirements.

    Data residency details

    Compliance posture

    GDPR and CCPA ready, with a Data Processing Agreement available on request. Our controls are designed against recognised frameworks and reviewed as we scale.

    Request our DPA

    Backups & reliability

    Automated, encrypted backups with point-in-time recovery, redundant infrastructure and monitored uptime — so your reporting cycle never stalls on us.

    At a glance

    What your risk team will want to check.

    TLS 1.2+ in transitAES-256 at restSAML / OIDC SSORole-based accessGDPR & CCPA readyEU + US residencyDPA availableFull audit loggingEncrypted backupsNever used for AI training

    Responsible disclosure

    Found a vulnerability? We want to hear from you. Report security concerns to our team and we'll acknowledge quickly and work with you on a coordinated fix. We do not pursue good-faith researchers who follow responsible-disclosure practices.

    security@engageinsights.io

    This page describes our security approach for general information and is not a warranty or part of any contract. Specific commitments, sub-processors and certifications are set out in your service agreement and Data Processing Agreement. For data-location specifics, see our data residency page; for processing terms, our DPA.

    Bring your security questionnaire.

    We'll walk your IT, risk and compliance teams through our controls, hosting and data-handling — and answer whatever your review process needs.