Security · Built around your boundaries

Your firm’s intelligence. Under your control.

Hermetica works in your environment, keeps conclusions connected to evidence, and leaves the final call with your team.

Explore the FAQs
The Hermetica mark between a shield and a lock, suspended in a sunlit stone interior

Your information. Your decisions.

Control is part of how the system works.

Investment work depends on confidential information and accountable judgment. Both need clear boundaries.

  1. Deployment boundary

    In your environment.

    Hermetica deploys into the customer environment and connects to structured and unstructured evidence across your existing systems.

  2. Decision provenance

    Connected to the evidence.

    The source, definition, and period stay attached to every conclusion. When evidence conflicts, what was used, rejected, and why stays visible.

  3. Human authority

    Accountable to your team.

    Human review remains explicit. Hermetica brings evidence and precedent into the work; the investment team makes the final call.

A control review shaped around your firm

Your requirements. The starting point.

We review the control requirements with your team against the proposed environment, architecture, and workflow.

Data retention

Agree retention periods, export requirements, and what should happen to information when the engagement ends.

Data governance

Map the systems in scope, the information they hold, and the people who should be able to access it.

Encryption management

Review protection in transit and at rest, key ownership, and the responsibilities within the proposed environment.

User authentication

Define identity, sign-in, and access requirements, including any single sign-on needs, for your deployment.

These are deployment-review topics. Specific controls and commitments depend on the agreed architecture and service terms.

The details that matter

Frequently asked questions.

Where is Hermetica deployed?

Hermetica deploys into the customer environment and connects to evidence across existing systems. The proposed environment, connection scope, and operating responsibilities are reviewed with your team before deployment.

Who can access our information?

Access requirements form part of the deployment review, including authorized users, administrative and support access, and identity or single sign-on needs. The applicable controls should be confirmed against your firm’s policies and the agreed architecture.

How is data encryption handled?

Encryption in transit and at rest, key management, and responsibility for operating those controls are reviewed for the proposed environment. Ask us to confirm the technical details for your deployment as part of security diligence.

Is our data used to train AI models?

Model-provider choices and data-use terms are part of the deployment review. Any restrictions on training, processing, and retention should be confirmed in the applicable agreement before confidential information is connected.

Can we trace a conclusion back to its sources?

Yes. The source, definition, and period behind every conclusion remain visible. When evidence conflicts, the record preserves what was used, what was rejected, and why. This supports review; it does not make a conclusion infallible or replace the investment team’s judgment.

What happens to our data when the engagement ends?

Retention, export, and deletion requirements should be agreed before deployment, including how they apply to connected systems and any information held by the service. The applicable service agreement governs these arrangements.

How do we start a security review?

Request a demo and mention your security requirements. Start with a high-level description of your environment and one investment workflow. We can use that context to scope the review with the relevant members of your team. Please do not include confidential materials in the request form.

Let’s work through the details

Confidence starts with a clear review.

Bring your environment, your control requirements, and one investment workflow. We’ll start there.

Start a security reviewShare requirements, not confidential materials.