ReconAxis

Security

How ReconAxis protects custodian, prime broker and administrator data — and where we are on the path to SOC 2.

Our approach

ReconAxis processes custodian, prime broker and fund administrator data on behalf of hedge funds, asset managers and fund administrators. We treat that data as confidential and design our controls around the questions your operations, compliance and allocator due-diligence teams will ask.

Controls in place today

Encryption at rest Databases, object storage and cache encrypted with AES-256 using managed keys.
Encryption in transit TLS 1.3 for traffic to the platform; TLS for internal cache connections.
Role-based access control Analyst, organization admin and super admin roles. Access is scoped to a single organization.
Multi-tenant isolation Every query is scoped by organization identifier; one customer cannot read another’s data.
Immutable audit logging Uploads, matches, break resolutions and administrative actions are recorded in an append-only log.
Authentication JSON Web Token sessions with expiry; Google OAuth supported.
Backups Automated database backups with point-in-time recovery; object storage versioning enabled.
Least-privilege infrastructure Application tasks run in private subnets with narrowly scoped cloud IAM roles.

Data residency

Production data is hosted on Amazon Web Services in the US East (N. Virginia) region. For customers who require Canadian data residency, a path to the AWS Canada (Central) region is documented and available on request.

Artificial intelligence & your data

AI features (break explanations, mapping suggestions) are designed for minimal data exposure: we send schema metadata and aggregated variance summaries to the model — not raw trade-level record values. Inference runs within our cloud provider’s security boundary.

SOC 2 status

ReconAxis is not yet SOC 2 certified. SOC 2 Type II is our roadmap target, and the controls described above are already aligned to the SOC 2 Trust Services Criteria (security, availability, confidentiality and processing integrity). We are happy to walk prospective customers through our current posture and roadmap under NDA.

Responsible disclosure

If you believe you have found a security vulnerability, please email security@reconaxis.com. We welcome good-faith research, aim to acknowledge reports within 72 hours, and will not pursue legal action against researchers who act in good faith.

Questions or a vendor security questionnaire?

Reach us at security@reconaxis.com and we’ll return your questionnaire (VSQ / CAIQ) with current documentation.