Data retention
Agree retention periods, export requirements, and what should happen to information when the engagement ends.
Security · Built around your boundaries
Hermetica works in your environment, keeps conclusions connected to evidence, and leaves the final call with your team.
Explore the FAQs
Your information. Your decisions.
Investment work depends on confidential information and accountable judgment. Both need clear boundaries.
Hermetica deploys into the customer environment and connects to structured and unstructured evidence across your existing systems.
The source, definition, and period stay attached to every conclusion. When evidence conflicts, what was used, rejected, and why stays visible.
Human review remains explicit. Hermetica brings evidence and precedent into the work; the investment team makes the final call.
A control review shaped around your firm
We review the control requirements with your team against the proposed environment, architecture, and workflow.
Agree retention periods, export requirements, and what should happen to information when the engagement ends.
Map the systems in scope, the information they hold, and the people who should be able to access it.
Review protection in transit and at rest, key ownership, and the responsibilities within the proposed environment.
Define identity, sign-in, and access requirements, including any single sign-on needs, for your deployment.
These are deployment-review topics. Specific controls and commitments depend on the agreed architecture and service terms.
The details that matter
Hermetica deploys into the customer environment and connects to evidence across existing systems. The proposed environment, connection scope, and operating responsibilities are reviewed with your team before deployment.
Access requirements form part of the deployment review, including authorized users, administrative and support access, and identity or single sign-on needs. The applicable controls should be confirmed against your firm’s policies and the agreed architecture.
Encryption in transit and at rest, key management, and responsibility for operating those controls are reviewed for the proposed environment. Ask us to confirm the technical details for your deployment as part of security diligence.
Model-provider choices and data-use terms are part of the deployment review. Any restrictions on training, processing, and retention should be confirmed in the applicable agreement before confidential information is connected.
Yes. The source, definition, and period behind every conclusion remain visible. When evidence conflicts, the record preserves what was used, what was rejected, and why. This supports review; it does not make a conclusion infallible or replace the investment team’s judgment.
Retention, export, and deletion requirements should be agreed before deployment, including how they apply to connected systems and any information held by the service. The applicable service agreement governs these arrangements.
Request a demo and mention your security requirements. Start with a high-level description of your environment and one investment workflow. We can use that context to scope the review with the relevant members of your team. Please do not include confidential materials in the request form.
Let’s work through the details
Bring your environment, your control requirements, and one investment workflow. We’ll start there.
Start a security reviewShare requirements, not confidential materials.