- Security & Data Handling
Security & Data Handling
This page describes how val409a protects the documents and information you share with us throughout an engagement.
How we handle your documents
Documents you share as part of the “Share your documents” step (cap tables, financial statements, articles of incorporation, transaction documents, etc.) are shared through [PLACEHOLDER: name of secure document-sharing platform/tool used] rather than unsecured email, and are accessible only to the analyst(s) and reviewing partner assigned to your engagement.
Technical safeguards
[PLACEHOLDER: confirm and list specific technical safeguards in place, e.g., encryption in transit and at rest, access controls/permissions, multi-factor authentication for internal systems.]
Organizational safeguards
All val409a analysts and staff are bound by confidentiality obligations covering client information. Access to client documents is limited to the individuals actively working on that engagement.
Subprocessors & vendors
We work with a small number of vetted service providers to support scheduling, document sharing, and internal operations. [PLACEHOLDER: list key subprocessors if required for transparency, e.g., calendar/scheduling tool, cloud storage provider.]
Data location
Because val409a operates from offices in India, Australia, the UAE, the United States, and Switzerland, your data may be stored or processed in more than one of these locations. [PLACEHOLDER: confirm primary hosting location(s) and any data residency commitments.]
Incident response
In the event of a security incident affecting client data, we will [PLACEHOLDER: confirm notification commitments and timeline, consistent with applicable law].
Reporting a security concern
If you have a security concern or believe you’ve identified a vulnerability, please contact us at info@val409a.com