W
WriteUp AI
Terms & PrivacyBook a Demo
Trust & Security

Security & Compliance

Your investor data is the most sensitive information in your business. We built WriteUp AI with institutional-grade security from day one — because your LPs expect nothing less.

256-bit
AES encryption at rest
TLS 1.3
Encryption in transit
SOC 2
Compliant infrastructure
RLS
Row-level data isolation

Built for Institutional Trust

WriteUp AI serves private equity firms, institutional investors, and asset managers who handle sensitive financial data every day. We understand that a breach of trust — even a perceived one — can end a client relationship.

That is why security is not a feature we added later. It is foundational to every architecture decision, every vendor relationship, and every line of code. Our platform is designed so that your data is never visible to other accounts, never used to train AI models, and never accessible to unauthorized parties.

Data Protection

Encryption

Every piece of data in WriteUp AI is encrypted — both while it moves between your browser and our servers, and while it sits in our database.

Encryption in Transit
All connections use TLS 1.3, the latest transport layer security standard. Every API call, file upload, and page load is encrypted end-to-end between your device and our infrastructure.
Encryption at Rest
Your financial documents, generated reports, and account data are encrypted using AES-256 at the storage layer. Even in the unlikely event of a physical breach, your data remains unreadable.

Data Isolation

WriteUp AI enforces strict tenant isolation at the database level. Every query is scoped to your account through row-level security policies — meaning there is no application-level code path that could accidentally expose one client's data to another.

This is not optional middleware or a feature toggle. It is enforced at the database engine level, so even if an application bug were introduced, the database itself would reject any cross-account data access.

Authentication & Identity

We use an enterprise-grade identity provider for all authentication. Your credentials are never stored in our database. Session management includes automatic expiration, secure cookie handling, and protection against common attack vectors including CSRF and session fixation.

Multi-factor authentication (MFA) is available for all accounts. For firms that require it, we support SSO integration through enterprise identity providers.

Infrastructure

WriteUp AI runs on SOC 2 Type II certified cloud infrastructure with automatic failover, redundant storage, and continuous backups. Our hosting providers maintain compliance with ISO 27001, SOC 2, and other internationally recognized security frameworks.

Application deployments are immutable and auditable. Every change to production is version-controlled, reviewed, and logged. There is no manual server access — all infrastructure is managed through code with a complete audit trail.

AI Processing

AI & Data Processing

When you generate a report, your financial data is sent to our AI processing pipeline. Here is exactly what happens — and what does not:

What we do
Process your data only to generate your report
Delete processing context after generation completes
Use enterprise API agreements with zero data retention
Validate every calculation with proprietary math verification
Store your generated reports securely in your account
What we never do
Use your data to train AI models
Share your financial data with other clients
Store your data on third-party AI servers
Allow AI providers to retain or log your data
Expose raw financial documents to any outside party

Financial Data Handling

We understand that T-12 operating statements, rent rolls, and budget files contain some of the most confidential information in your business. Our handling of this data reflects that responsibility.

Uploaded documents are stored in encrypted, access-controlled storage buckets scoped to your account. They are only accessed during report generation and are never exposed to other users, external services, or internal personnel without explicit authorization. Every report includes a proprietary math verification audit trail so you can trust the numbers before sending to your investors.

Payment Security

All payment processing is handled by a PCI DSS Level 1 certified payment provider — the highest level of certification in the payments industry. WriteUp AI never stores, processes, or has access to your credit card numbers, bank account details, or other payment credentials. Billing is managed entirely through our payment provider's secure infrastructure.

Compliance

Compliance & Standards

Our infrastructure providers and technology partners maintain the following certifications and compliance standards. We continuously evaluate our own security posture against these frameworks.

SOC 2 Type II (Infrastructure)Compliant
ISO 27001 (Infrastructure)Compliant
PCI DSS Level 1 (Payments)Compliant
GDPR (Data Protection)Compliant
CCPA (California Privacy)Compliant
HIPAA (Not Applicable)N/A
Encryption at RestAES-256

Internal Access Controls

Access to customer data within our organization follows the principle of least privilege. Only authorized personnel with a documented business need can access production systems. All access is logged, auditable, and subject to periodic review.

We do not access your financial documents or generated reports unless you explicitly request support and grant permission. There is no standing access to customer data for any employee.

Monitoring & Logging

Our systems are continuously monitored for performance, availability, and security events. We maintain detailed logs of authentication events, API access, and administrative actions. Anomalous patterns trigger automated alerts that are reviewed by our team.

Incident Response

In the event of a confirmed security incident, our response plan includes immediate containment and assessment of the scope and impact, notification to affected customers within 72 hours (or sooner as required by applicable law), a thorough root cause analysis, and implementation of measures to prevent recurrence.

We believe in transparency. If an incident affects your data, you will hear about it directly from us — not from a news article.

Vendor & Supply Chain Security

We carefully vet every third-party service in our stack. Each vendor is evaluated for security certifications, data handling practices, breach history, and contractual protections. We maintain enterprise-level agreements with all critical infrastructure providers that include data processing terms, zero-retention clauses where applicable, and incident notification requirements.

Data Retention & Deletion

Your data is retained for the duration of your active account. Financial documents are stored as long as you need them for historical reporting and comparison. If you cancel your subscription, you may request a complete export of your data before we initiate deletion.

Upon receiving a verified deletion request, we will permanently remove all personal data, uploaded documents, and generated reports within 30 days. Anonymized, aggregate usage data may be retained for product improvement purposes.

Common Questions

Frequently Asked Questions

Can other clients see my financial data?
No. Row-level security policies enforce complete data isolation at the database level. There is no code path — intentional or accidental — that could expose your data to another account.
Is my data used to train AI models?
No. We use enterprise AI agreements with zero data retention. Your financial documents and report content are never used for model training, fine-tuning, or any purpose beyond generating your specific report.
What happens to my data if I cancel?
Your data remains accessible for 30 days after cancellation so you can export anything you need. After that, all personal data, documents, and reports are permanently deleted upon request.
Do you have a SOC 2 report?
Our infrastructure providers maintain SOC 2 Type II certification. We are evaluating our own SOC 2 audit timeline and will update this page when available. In the meantime, we are happy to walk through our security architecture in detail — just ask.
Can I get a security questionnaire completed?
Yes. We regularly complete security questionnaires for institutional clients. Contact us at the email below and we will prioritize your request.
Where is my data stored geographically?
All data is stored in the United States on SOC 2 certified infrastructure. If you have specific data residency requirements, please contact us to discuss your needs.

Questions or Concerns?

Security is a conversation, not a checkbox. If you have questions about our practices, need a security questionnaire completed, or want to discuss your firm's specific requirements, we are here.

Walker Ventures LLC

d/b/a WriteUp AI

Email: security@writeupai.com

Schedule a Security Review

Last reviewed: April 2026  •  © 2026 Walker Ventures LLC. All rights reserved.