Our approach

Security principles that guide every layer of the platform.

Hilo Labs Limited, which operates Fulcra AI, establishes policies and technical controls designed to protect customer data throughout its lifecycle.

01

Least privilege

Access is limited to those with a legitimate business need and granted based on role and tenant scope.

02

Defense in depth

Security controls are layered across infrastructure, application, and operational processes.

03

Encryption everywhere

Customer data is encrypted at rest and in transit using industry-standard protocols.

04

Data minimization

We process customer content only to deliver the diligence analysis and workflow features of the platform.

Data protection

How your data is protected.

Data at rest
Customer documents and platform data are stored in encrypted form, using managed, industry-standard key management.
Data in transit
All data transmitted between users, our services, and third-party integrations is protected with TLS.
Tenancy
Each customer operates in a single-tenant environment with isolated storage, hosted in US AWS regions.

AI & your data

Your data room is for diligence, not model training.

Fulcra AI uses frontier language models to power analysis, but your deal data stays yours.

No training on your data
Your data room contents are never used to train AI models.
Purpose-limited processing
Customer content is processed only to deliver the diligence analysis and workflow features you use on the platform.
Customer agreements
How Customer Content is handled is governed by the written agreement between Hilo Labs and each customer, including any data processing agreement. See our Privacy Policy for more detail.

Infrastructure

Built on AWS, hosted in the United States.

Cloud hosting
Fulcra AI runs on Amazon Web Services (AWS) infrastructure in US regions.
Isolated storage
Each customer's documents and analysis data are stored in tenant-scoped, isolated environments.
Secrets management
Application secrets and configuration are stored securely using managed secret storage, with access restricted to authorized services.

Access & authentication

Controlled access for every user.

Identity provider
Platform authentication is handled through a managed identity provider, with secure token-based access to the application.
Role-based access
Users are granted access based on their role within their organization. Data queries are scoped to the tenant, preventing cross-customer access.
Account lifecycle
Access is provisioned for authorized users and removed when a user's employment or engagement ends.

Application security

Secure development and operations.

Input validation
Data received from users, APIs, and background workers is validated at system boundaries before it reaches business logic.
Dependency management
We monitor and update third-party dependencies, including automated dependency and vulnerability scanning.
Least-privilege services
Platform services operate with narrowly scoped permissions, limiting the blast radius of any individual component.

Compliance

Building toward independent assurance.

We have built Fulcra with enterprise-grade security protocols and are actively in the process of SOC 2 certification.

SOC 2
Fulcra AI is actively pursuing SOC 2 certification. We will update this page when certification is complete.
Customer agreements
Enterprise customers can request security documentation, including our data processing agreement, as part of onboarding.

Get started

See Fulcra AI on a live data room.

Book a demo to walk through the platform, from ingest to IC-ready memo, configured to how your firm runs deals.