Security & data handling

Built for sensitive investment workflows.

Portfolio holdings and internal theses are among the most sensitive material a firm holds. Here is what is in place today, and what isn't yet — stated plainly, because you'll ask in the first meeting either way.

In place today

Current architecture.

Audit trail
Every conclusion, score and thesis status change is recorded with its source document, section and timestamp. The trail is exportable.
Encryption
TLS for all communication in transit; encryption at rest for stored portfolio and thesis data.
Data separation
Customer data is logically separated. Portfolio contents and theses are never used to serve another customer's output.
No brokerage credentials
Research pilots require no account access, no credentials and no order permissions. There is no execution path in the product.
Minimal collection
We ask for the securities you want monitored and the thesis you want tracked. Not positions, not sizes, not performance.

Roadmap

On the roadmap, not yet delivered.

Role-based access

Team accounts with per-role permissions over portfolios and theses.

Private model deployment

An architecture where inference runs inside your environment. Under evaluation.

SSO and directory sync

SAML/OIDC sign-in for firms that require it.

On certifications.

We do not currently hold SOC 2, ISO 27001 or any equivalent certification, and we don't claim otherwise. If a formal assessment is a requirement for your firm, tell us during the pilot conversation and we'll be direct about timing.

Security questions before a pilot are welcome. Write to support@pullelainnovation.com and we'll answer in writing.