Trust posture
Investment-grade by design.
Family offices, VCs and PE firms hold their data and processes to a high bar. Hebrides is built around that: certified controls, least-privilege access, a complete audit trail, and sources for every figure.
Certified
SOC 2 Type II
AICPA Trust Services Criteria
Certified
ISO/IEC 27001:2022
Certified information security management system
The commitments
- SOC 2 Type II
- Controls independently verified against the AICPA Trust Services Criteria.
- ISO 27001
- Our information security management system is certified to ISO/IEC 27001:2022.
- No training on your data
- Your deal information is not used to train models.
- Source transparency
- Every figure and claim traced back to the document it came from.
- Audit logs
- Every upload, download, chat, generation and access change recorded and reviewable.
- Role-based access
- Admin, Manager and User roles, with access granted per portfolio and per deal.
- Two-factor authentication
- Authenticator-app 2FA available on every account.
- Modern, secure data practices
- Built to industry-standard data security throughout.
Access control
The minimum access each person needs.
Access flows through portfolio and deal membership. Invite a teammate with the role they need, and change it when their work changes.
- Admin
- Sees every portfolio and deal. Invites teammates and sets roles, reads the audit log and amends the firm profile.
- Manager
- Sees every portfolio and deal. Creates and deletes portfolios and deals, and sets pipeline stages.
- User
- Sees only the portfolios and deals they are a member of, and edits the deals they belong to.
- External Dataroom Uploader
- Uploads into one assigned dataroom. Nothing else is visible.
Accountability
Every action recorded and reviewable.
Admins see every recorded action across the firm, newest first, and can filter by action, person and date: file upload, file download, chat message, document generation, dashboard view, user assignment, portfolio access, deal access. Valuation overrides are logged with a reason, and history is never rewritten.
Try it · Switch roles to see what each one can see, or filter the audit log. Sample data.
Your data stays yours
Deal information is never used to train models. It is used to produce your firm’s analysis and nothing else.
Least access to your drives
With Google Drive, only the files you choose in Google’s own picker are shared. OneDrive imports bring in the files and folders you select.
Deletion that means deletion
Delete a file and its extracted text and search index entries go with it, so nothing can cite it afterwards.
Security FAQ
Security questions.
Is Hebrides SOC 2 compliant?
Yes. Hebrides holds SOC 2 Type II, with controls independently verified against the AICPA Trust Services Criteria. Reports are available through our Trust Centre.
Is Hebrides ISO 27001 certified?
Yes. Our information security management system is certified to ISO/IEC 27001:2022.
Is our deal data used to train AI models?
No. Your deal information, documents and firm profile are never used to train models.
Who at our firm can see a deal?
Admins and Managers see every portfolio and deal; Users see only the portfolios and deals they are members of. External uploaders can only add files to the one dataroom assigned to them.
What happens when we delete a file?
The file, its extracted text and its search index entries are removed, so chats, valuations and reports can no longer cite it.
Where can we get security documentation?
Our Trust Centre holds our certifications and policies. For a security questionnaire or a call with the team, contact us.
Book a walkthrough
Talk to us about your security review.
We’ll walk your team through our controls, certifications and the way Hebrides handles your data.
Or write to sales@allermuircapital.com