Hectofy — Data Processing Addendum (DPA) & Security Policy
Effective Date: August 12, 2026
Last Updated: August 2026
1. Executive Summary
This Data Processing Addendum ("DPA") supplements the Hectofy Master Terms of Service and sets forth the technical, organizational, and security measures implemented by Hectofy Inc. to protect Customer Personal Data and confidential portfolio company financial metrics.
2. Technical & Organizational Security Controls (SOC 2 Alignment)
2.1 Encryption Standards
- Data in Transit: All API requests, dashboard traffic, and webhook transmissions enforce TLS 1.3 encryption with strong cipher suites.
- Data at Rest: Database volumes, snapshot logs, and API tokens are encrypted at rest using industry-standard AES-256 bit encryption.
2.2 Multi-Tenant Cryptographic Isolation
- Database Boundary Enforcement: Every SQL query and API endpoint explicitly verifies the authenticated Customer Fund ID (
fund_id). - Cross-Tenant Prevention: Cross-tenant data leakage is prevented at both the database schema layer and API middleware layer.
2.3 Access Control & Employee "Break-Glass" Policies
- Zero Default Access: Hectofy engineering and support personnel have zero default access to Customer fund financial ledgers or LP reports.
- Time-Limited Emergency Access: Administrative support access requires explicit customer authorization, 2-factor authentication, and is logged in immutable audit logs.
2.4 Data Backup & Disaster Recovery
- Daily Automated Backups: Production databases are backed up daily with point-in-time recovery capabilities.
- Redundancy & Uptime: Infrastructure is deployed across multi-zone cloud facilities enforcing 99.5%+ uptime SLAs.
3. Sub-Processor Registry
Hectofy engages trusted sub-processors for infrastructure, database hosting, and report rendering:
| Sub-processor | Purpose | Location | Security Certification |
|---|---|---|---|
| Render Services Inc. | Cloud Application Hosting & API Nodes | USA | SOC 2 Type II, ISO 27001 |
| Resend Inc. | Transactional Email Dispatch (Resend API) | USA | SOC 2 Type II |
| Google Cloud Platform | Gemini 3.5 Pro Enterprise AI Processing | USA | SOC 2 Type II, ISO 27001 |
| Plaid Inc. | Read-Only Financial Ledger Integrations | USA | SOC 2 Type II, ISO 27001 |
4. Security Incident Notification
In the event of a confirmed Security Incident impacting Customer Data, Hectofy will notify affected Customers via email without undue delay and no later than 72 hours after becoming aware of the incident, providing detailed remediation steps.
5. Contact Information
Security Team: security@hectofy.com | Hectofy (Registered entity address details will be updated upon final incorporation).