AxtaraContact
Controls, security & data

The diligence answers, before the questionnaire.

What we have, what is in progress, and what is targeted — stated plainly. Where a date is a target, it is labelled a target.

Certifications and attestations

SOC 1 Type II

Examination in progress; report targeted Q4 2026. Stated plainly because you will ask.

SOC 2 Type II / ISO 27001

SOC 2 Type II targeted H1 2027, ISO 27001 to follow. Current control set available under NDA.

Cash controls and segregation of duties

No unilateral cash movement

Segregation of duties on every account. No individual can initiate and approve a payment — dual authorisation on all disbursements.

Access control, encryption, data residency, retention and deletion

Encryption

Data encrypted in transit and at rest.

Data residency

US-region storage.

Access

Access to your fund's data is limited to the named team on your mandate.

Retention, export and deletion

Full export in native formats whenever you ask — including when you leave. Data deleted on request.

Delivery model and personnel

Named team

Every fund is assigned a named client controller and a named senior accountant — never more than four funds per accountant.

Continuity

Every mandate has a documented second, and any staffing change comes with a supervised handover. If a handover ever slips, that quarter's fee is credited.

Reviewer accountability

Named reviewer on every statement

Every statement carries a named reviewer — a qualified accountant who signed it before it reached you or your investors.

Full control documentation

The complete control set is shared under NDA. Tell us where to send it.

Inbound security questionnaires: security@axtara.ai — or route them through the contact page.