At L14, security and privacy are foundational to everything we build. Serving ultra-high-net-worth families and institutional partners demands the highest standards of data protection. Our platform is engineered with defense-in-depth security, rigorous access controls, and comprehensive compliance with international data protection regulations.
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Designated restricted-class fields receive additional column-level encryption.
Fine-grained permissions enforced at the database level through Row Level Security policies, ensuring users only access data they are authorized to see.
Institutional data is fully isolated at the database level. Cross-tenant access is prevented by design through enforced foreign key constraints and RLS policies.
Data access and modification are recorded in an append-only audit log. Row-level security policies prevent audit records from being altered or removed through the application; no operator or administrator account can rewrite them.
Multiple authentication methods are supported: passwordless magic-link sign-in, email and password with multi-factor authentication, one-time codes, and Google OAuth.
Hosted on enterprise-grade cloud infrastructure with automatic scaling, DDoS protection, and a globally distributed edge network. Application data is held in the European Union.
We are actively pursuing SOC 2 Type II certification covering security, availability, confidentiality, processing integrity, and privacy. Gap assessment has been completed with remediation underway.
We are working toward full compliance with the General Data Protection Regulation. Application data is held in the European Union with per-institution isolation and append-only audit logging. Retention, deletion, legal-hold, and consent mechanisms are built into the platform, and Data Subject Access Requests are handled as a supervised manual process within the statutory 30-day window. Automated data export, portability, and self-service privacy controls are still being rolled out.
Aligned with the revised Swiss Federal Act on Data Protection (nDSG/FADP) effective September 2023, including data processing transparency and cross-border transfer safeguards.
Platform architecture and data handling practices are aligned with FINMA circular requirements for outsourcing and operational risk management in financial services.
Our retention policy keeps active member data for the duration of membership plus 5 years, and financial records for 10 years to meet regulatory requirements. Retention is governed and applied as policy today; the platform's automated per-category lifecycle enforcement is being rolled out.
Members and institution contacts can request a copy of their personal data. Each request is answered within the GDPR-mandated 30-day window and is tracked against that deadline. Collection and delivery are performed manually today; the automated collection, packaging, and self-service delivery pipeline is still in development.
Deletion requests are honoured by anonymising the member's personal identifiers, including name, contact details, date of birth, and nationality, after a 30-day grace period. Legal holds can freeze a record from deletion, and each action is written to a deletion audit log. Cascading erasure across all related records, and the purging of data exports generated before deletion, are still in development.
Consent is recorded per individual in an append-only register that captures the actor, source, and version of each decision, so the history cannot be rewritten. Consent can be withdrawn at any time by contacting us; self-service withdrawal from the member application is still in development.
If you have questions about our security practices or want to report a vulnerability, please contact our security team.
security@l14.com