Skip to content
Hectofy
← Back to Hectofy
LEGAL / HECTOFYPrivacy PolicyTerms of ServiceCancellation & Refund PolicyData Processing Addendum

Hectofy — Data Processing Addendum (DPA) & Security Policy

Effective Date: August 12, 2026
Last Updated: August 2026


1. Executive Summary

This Data Processing Addendum ("DPA") supplements the Hectofy Master Terms of Service and sets forth the technical, organizational, and security measures implemented by Hectofy Inc. to protect Customer Personal Data and confidential portfolio company financial metrics.


2. Technical & Organizational Security Controls (SOC 2 Alignment)

2.1 Encryption Standards

  • Data in Transit: All API requests, dashboard traffic, and webhook transmissions enforce TLS 1.3 encryption with strong cipher suites.
  • Data at Rest: Database volumes, snapshot logs, and API tokens are encrypted at rest using industry-standard AES-256 bit encryption.

2.2 Multi-Tenant Cryptographic Isolation

  • Database Boundary Enforcement: Every SQL query and API endpoint explicitly verifies the authenticated Customer Fund ID (fund_id).
  • Cross-Tenant Prevention: Cross-tenant data leakage is prevented at both the database schema layer and API middleware layer.

2.3 Access Control & Employee "Break-Glass" Policies

  • Zero Default Access: Hectofy engineering and support personnel have zero default access to Customer fund financial ledgers or LP reports.
  • Time-Limited Emergency Access: Administrative support access requires explicit customer authorization, 2-factor authentication, and is logged in immutable audit logs.

2.4 Data Backup & Disaster Recovery

  • Daily Automated Backups: Production databases are backed up daily with point-in-time recovery capabilities.
  • Redundancy & Uptime: Infrastructure is deployed across multi-zone cloud facilities enforcing 99.5%+ uptime SLAs.

3. Sub-Processor Registry

Hectofy engages trusted sub-processors for infrastructure, database hosting, and report rendering:

Sub-processor Purpose Location Security Certification
Render Services Inc. Cloud Application Hosting & API Nodes USA SOC 2 Type II, ISO 27001
Resend Inc. Transactional Email Dispatch (Resend API) USA SOC 2 Type II
Google Cloud Platform Gemini 3.5 Pro Enterprise AI Processing USA SOC 2 Type II, ISO 27001
Plaid Inc. Read-Only Financial Ledger Integrations USA SOC 2 Type II, ISO 27001

4. Security Incident Notification

In the event of a confirmed Security Incident impacting Customer Data, Hectofy will notify affected Customers via email without undue delay and no later than 72 hours after becoming aware of the incident, providing detailed remediation steps.


5. Contact Information

Security Team: security@hectofy.com | Hectofy (Registered entity address details will be updated upon final incorporation).

Privacy PolicyTerms of ServiceCancellation & Refund PolicyData Processing Addendum
Hectofy

A clearer view of your portfolio.

HomeExplore demo
© 2026 Hectofy. All rights reserved.