Security
Fund data is among the most sensitive information a business handles. Quartermark is built on the principle that your data is yours: isolated, encrypted, and never used to benefit anyone but you.
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Tenant isolation
Each customer's data is logically isolated. One fund's data is never visible to, or commingled with, another's.
Your data is never training data
We do not train AI models on your documents or financials. Model improvements come from our own testing and synthetic data, never from customer content.
Access controls
Role-based permissions govern who on your team can view, edit, and approve. Access within Quartermark follows the principle of least privilege.
Audit logs
Every upload, edit, approval, and export is logged and reviewable.
Infrastructure
Quartermark runs on established cloud infrastructure providers that maintain their own industry-standard compliance programs.
Data deletion
Leave at any time and take your data with you. Full export on request, deletion on request.
Compliance roadmap
We are an early-stage company and say so plainly: formal certifications such as SOC 2 are on our roadmap, not on our wall. We're happy to walk your team through our security practices in detail — ask us anything.