Enterprise-grade security for institutional investors
Your fund data is protected by the same security standards trusted by the world's leading financial institutions.
Certifications & Compliance
We maintain the highest standards of security compliance
SOC 2 Type II
Annual third-party audit of security, availability, processing integrity, confidentiality, and privacy controls.
GDPR Compliant
Full compliance with EU General Data Protection Regulation for data privacy and protection.
ISO 27001
Information security management system certification demonstrating systematic approach to data security.
CCPA Ready
California Consumer Privacy Act compliance for US data privacy requirements.
Security Architecture
Multiple layers of protection for your sensitive fund data
Data Protection
- 256-bit AES encryption at rest
- TLS 1.3 encryption in transit
- Hardware security modules (HSM) for key management
- Automated backup with point-in-time recovery
- Data residency options (US, EU, APAC)
Access Control
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- Single sign-on (SSO) with SAML 2.0
- IP allowlisting
- Session management and timeout controls
Monitoring & Audit
- Complete audit trail of all actions
- Real-time security monitoring
- Anomaly detection and alerting
- Detailed access logs
- Compliance reporting
Infrastructure
- Hosted on AWS with multi-AZ redundancy
- 99.99% uptime SLA
- DDoS protection
- Web application firewall (WAF)
- Regular penetration testing
Your data, your control
We believe in complete transparency about how your data is handled. You always maintain full ownership and control.
- We never sell or share your data with third parties
- You can export all your data at any time
- Data is deleted upon contract termination
- Clear data processing agreements available
- Regular privacy impact assessments
Built on world-class infrastructure
Supranova is hosted on Amazon Web Services (AWS), leveraging their industry-leading security infrastructure including multi-region redundancy, automatic failover, and continuous monitoring.