Security & governance

The most sensitive data in private markets — and an honest account of how we handle it.

Deal documents, financials, LP information, and MNPI. Here’s what we do, what we don’t, and what we haven’t built yet.

We don’t train on your data.

AKAXA does not use your deal materials to train or fine-tune any model. For the AI providers we call, we rely on their published commercial API terms.

We don’t sell or share it.

We do not provide personal data to third parties for their own marketing. The sub-processors we use are named on a published list.

Tamper-evident audit trail

Analysis and access events are on the record.

Events are written once to an append-only log, each entry sealing the hash of the one before it (SHA-256, chained). Any alteration breaks the chain, and the chain is verifiable on demand.

Append-only — entries are written once. There is no edit-in-place.Live
Chained — each entry seals the hash of the entry before it.Live
Defensible — designed for IC, LP, and regulatory review. No external party has assessed it.Un-assessed
Governed by design

AI moves the work. People hold the authority.

A permission fence

Scopes what each person can retrieve. Retrieval is filtered by role and grant, not by good intentions.

Nothing auto-approved

Every material change waits for a person. Unsourced claims are labelled “needs verification,” and a failed validation blocks the export.

Privacy, by jurisdiction

Where a local law grants a stronger right, we apply the stronger right.

Hong Kong PDPO

AKAXA operates under the Personal Data (Privacy) Ordinance (Cap. 486).

GDPR · UK GDPR · CCPA/CPRA

Rights supported for EU/EEA, UK, and California data subjects, including do-not-sell and data-subject requests.

Encryption & infrastructure

Provider-managed, and stated as such.

In transit & at rest

Encrypted in transit (TLS 1.2+) and at rest by our infrastructure providers (AES-256 or equivalent).

Access & hardening

Role-based access, rate limiting, hardened headers, encrypted secrets. Responsible disclosure: security@akaxa.io.

Where we are, honestly

Saying otherwise would be the first thing we’d ask our own product to catch.

SHA-256 chained audit log · published sub-processor list · information-barrier request & approvalLive
Query-level barrier enforcement · per-recipient redaction on exportsBuilt · in shadow
SOC 2 Type II · ISO 27001 — not certifiedRoadmap

Have a security questionnaire? Send it to security@akaxa.io — we answer in full, including the gaps.