The most sensitive data in private markets. Treated like it.
Deal documents, financials, LP information, and MNPI. Security controls are being prepared for institutional diligence, and actions are auditable after the fact.
What we do not do with your data.
We do not train on your data.
AKAXA does not use your deal documents, financials, or analyses to train or fine-tune any model. For the AI providers we call, we rely on their published commercial API terms, which state that content submitted through those APIs is not used for training; we have not independently audited that. We have not negotiated separate zero-retention terms, and we say so rather than implying we have.
We do not sell or share it.
We do not provide personal data to third parties for their own marketing. The sub-processors we use are named on this page, with the purpose of each and the training position in its own published terms.
AKAXA is designed so that incomplete work does not present as finished.
An unsourced claim is labelled needs verification rather than presented as fact, and a failed validation can block the export outright. Your name goes on what leaves this system — so it does not leave until it can be defended.
Analysis and access events are on the record.
Analysis, provisioning, sync and agent events are written to an append-only audit log, cryptographically chained with SHA-256 — each entry carrying the hash of the one before it. Break any link and verification fails, including on the entry itself. It is not a blanket record of every read of personal data, and is not claimed as one.
Any alteration breaks the chain.
Privacy, by jurisdiction.
Where a local law grants a stronger right, we apply the stronger right.
Hong Kong PDPO
AKAXA operates under the Personal Data (Privacy) Ordinance (Cap. 486). We do not use personal data for direct marketing where the applicable law requires consent and we do not hold it.
GDPR · UK GDPR
Rights supported for EU/EEA and UK data subjects. A Data Processing Agreement is offered as a template; none has been executed. Where a local law grants a stronger right, we apply the stronger right.
CCPA / CPRA
California privacy rights supported, including Do-Not-Sell and data-subject requests.
Encryption and infrastructure.
Where we are, honestly.
We are pre-SOC 2. Saying otherwise would be the first thing we ask our own product to catch.
We’d rather show you the flag than tell you it’s on.
Have a security questionnaire?
Send it to hello@akaxa.io — we answer them in full, including the gaps.