Orderly server racks behind a glass partition in a data centre.
Security and data

Your data. In safe hands.

Capital calls, cap tables and purchase contracts are among the most confidential documents an investor holds. This page says plainly what we do with them.

Where the data is

Region
AWS in Stockholm, Sweden. Application, database and documents all run there. Nothing is stored outside the EU.
Storage
Database and documents are encrypted at rest and backed up automatically. Documents open only through the application with a valid session.
Data centre certifications
AWS's data centres are certified under ISO 27001 and SOC 2, among others. Valued itself has not yet been separately audited, and we say so.

Who can see it

Isolation between accounts
Every table is protected by row-level security policies in the database. A query runs as the signed-in account and cannot return another account's rows, whatever the application code does.
Sign-in
E-mail and password with a verified e-mail address, or Google sign-in. Sessions expire and have to be renewed.
Two-factor sign-in
You can add an authenticator app as a second factor. Once you have, the server refuses every request that has only passed the password, on the database, the document store and the functions alike. A change of password or of the second factor is confirmed to you by e-mail.
Team members
An account owner can invite others with a defined role. Invitations are single-use links that expire.
Our own access
Nobody at Valued has standing access to your portfolio data. If a support case needs someone to look at it, we ask you first, for that case.

How documents are read

Model provider
Extraction uses Anthropic's Claude models through the Anthropic API. The document and the extracted figures are stored by Valued in the EU; the API call is the only point at which document content leaves our infrastructure.
Training
Under Anthropic's commercial terms, content sent through the API is not used to train models.
What is sent
The document itself, and the minimum context needed to match it to your record, such as the fund name. Not your portfolio, not other documents.
Approval
No extraction is booked automatically. A person approves each one, and the source document stays attached to the booking.

In transit and in operation

Encryption in transit
TLS for every connection: browser to application, application to database, application to the model API.
Firewall and sign-in limits
A web application firewall in front of the API limits repeated sign-in attempts and blocks known malicious requests.
Audit trail
Administrative actions on the infrastructure are logged. Every booking in your record keeps the document it was made from.
Monitoring
Alarms and automated threat detection go straight to the people who run the service.

Your rights and your exit

GDPR
Digital Pioneers GmbH is the controller for account data and the processor for the portfolio data you upload. Access, correction, export and deletion are available to you directly.
Export
Funds, cash flows, holdings and loans export to Excel from within the application. Every document can be downloaded as the file it arrived as.
Deletion
You can delete your account from settings. Portfolio data and documents are removed; backups age out on their retention schedule.
Sub-processors
Amazon Web Services (hosting, EU), Anthropic (document reading), Stripe (payments), SendGrid (transactional e-mail). We will tell you before adding one.

Reporting a vulnerability

If you find a security problem, write to security@valued.com. We acknowledge reports within two working days, keep you informed while we fix the issue, and credit you if you would like us to. Please do not access data that is not yours while testing.

Questions from your compliance side

Family offices and advisers sometimes need a written answer to a questionnaire before they can use a service. Send it to us. We answer these ourselves, and we would rather answer honestly than tick a box.

Contact