Security & Compliance
Sovereign Infrastructure.
Decks under NDA. Anti-portfolio data. IC dissent memos. Cap-table commingling notes. This is the most sensitive material your firm holds — and the data SaaS vendors monetize most aggressively. We do not retain it. We do not train on it. We do not aggregate it. The audit produces a Defensible Audit Log™; the substrate it ran on does not survive the session.
// THE SECURITY PROTOCOL
Built for the Risk Officer.
Zero Data Retention
We do not train on your data. Period.
Enterprise Clarity deployments run on a zero-retention architecture. Decks, financial models, and cap tables are processed in ephemeral compute and purged on completion. The audit produces a Defensible Audit Log™; the substrate it ran on does not survive the session.
Encryption
Encrypted at every stage of the pipeline.
- At rest: AES-256
- In transit: TLS 1.3
- API access: token-based auth with scoped permissions
Infrastructure
Enterprise-grade cloud with security and performance guarantees.
- Compute: Google Cloud Platform (Enterprise Tier)
- Edge: Cloudflare WAF, DDoS protection, CDN
- Deployment: multi-tenant (emerging managers) or dedicated instance (enterprise funds)
Jurisdiction
Headquartered in Singapore — a recognized financial center under English Common Law.
- Legal framework: Singapore Companies Act, PDPA compliance
- IP protection: four U.S. provisional patents filed
- Data sovereignty: processing region configurable per deployment
// SOVEREIGN-GRADE RUNTIME
The runtime is legally vetted, not just encrypted.
The JUDGE Protocol™ — askOdin's runtime circuit breaker — intercepts probabilistic hallucinations before they reach an output, isolates the offending variable, and hot-loads a corrective constraint without altering the underlying model. It is the only component of the stack to carry a national-security clearance.
Clearance
U.S. Prov. Patent No. 64/017,488
IPOS §34 National Security Clearance
Issued 2026-03-26
Compliance Roadmap
- Zero Data Retention policy
- AES-256 / TLS 1.3 encryption
- Google Cloud Enterprise Tier
- Cloudflare WAF + DDoS protection
- PDPA (Singapore) compliance
- IPOS §34 clearance (JUDGE Protocol)
- SOC 2 Type I certification
- GDPR Data Processing Agreement
- Penetration testing (third-party)
- SOC 2 Type II certification
- ISO 27001
- On-premise deployment option
Questions about security?
We welcome security reviews and provide detailed technical documentation for your compliance team.