Sign InSign Up

Trust & Security

How we protect your data and maintain compliance

At L14, security and privacy are foundational to everything we build. Serving ultra-high-net-worth families and institutional partners demands the highest standards of data protection. Our platform is engineered with defense-in-depth security, rigorous access controls, and comprehensive compliance with international data protection regulations.

Security Architecture

End-to-End Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Designated restricted-class fields receive additional column-level encryption.

Role-Based Access Control

Fine-grained permissions enforced at the database level through Row Level Security policies, ensuring users only access data they are authorized to see.

Multi-Tenant Data Isolation

Institutional data is fully isolated at the database level. Cross-tenant access is prevented by design through enforced foreign key constraints and RLS policies.

Append-Only Audit Logging

Data access and modification are recorded in an append-only audit log. Row-level security policies prevent audit records from being altered or removed through the application; no operator or administrator account can rewrite them.

Multi-Factor Authentication

Multiple authentication methods are supported: passwordless magic-link sign-in, email and password with multi-factor authentication, one-time codes, and Google OAuth.

Managed Cloud Infrastructure

Hosted on enterprise-grade cloud infrastructure with automatic scaling, DDoS protection, and a globally distributed edge network. Application data is held in the European Union.

Compliance & Certifications

SOC 2 Type II

In Progress

We are actively pursuing SOC 2 Type II certification covering security, availability, confidentiality, processing integrity, and privacy. Gap assessment has been completed with remediation underway.

GDPR

In Progress

We are working toward full compliance with the General Data Protection Regulation. Application data is held in the European Union with per-institution isolation and append-only audit logging. Retention, deletion, legal-hold, and consent mechanisms are built into the platform, and Data Subject Access Requests are handled as a supervised manual process within the statutory 30-day window. Automated data export, portability, and self-service privacy controls are still being rolled out.

Swiss Data Protection Act (nDSG)

Aligned

Aligned with the revised Swiss Federal Act on Data Protection (nDSG/FADP) effective September 2023, including data processing transparency and cross-border transfer safeguards.

FINMA Guidelines

Aligned

Platform architecture and data handling practices are aligned with FINMA circular requirements for outsourcing and operational risk management in financial services.

Data Protection Practices

Data Retention Policies

Our retention policy keeps active member data for the duration of membership plus 5 years, and financial records for 10 years to meet regulatory requirements. Retention is governed and applied as policy today; the platform's automated per-category lifecycle enforcement is being rolled out.

Data Subject Access Requests

Members and institution contacts can request a copy of their personal data. Each request is answered within the GDPR-mandated 30-day window and is tracked against that deadline. Collection and delivery are performed manually today; the automated collection, packaging, and self-service delivery pipeline is still in development.

Right to Deletion

Deletion requests are honoured by anonymising the member's personal identifiers, including name, contact details, date of birth, and nationality, after a 30-day grace period. Legal holds can freeze a record from deletion, and each action is written to a deletion audit log. Cascading erasure across all related records, and the purging of data exports generated before deletion, are still in development.

Consent Management

Consent is recorded per individual in an append-only register that captures the actor, source, and version of each decision, so the history cannot be rewritten. Consent can be withdrawn at any time by contacting us; self-service withdrawal from the member application is still in development.

Infrastructure Details

Application Hosting
Vercel Edge Network (Global CDN)
Database
Supabase (PostgreSQL) with RLS
Encryption at Rest
AES-256
Encryption in Transit
TLS 1.3
Backups
Daily automated with point-in-time recovery
Monitoring
24/7 automated error tracking and alerting

Security Questions?

If you have questions about our security practices or want to report a vulnerability, please contact our security team.

security@l14.com

The Private Life Office. A family office takes care of the money. We take care of everything else.

© Copyright 2026 Louis Fourteen. All Rights Reserved.

Legal
  • Trust & Security