Trust and governance

Security &
Data Governance

PEVio is built to support institutional diligence with controls designed to protect client information, restrict access and preserve a traceable path from evidence to decision.

Client dataIsolated and governedPrivate · Encrypted · Reviewable
Platform safeguards

Protection is applied across the analysis environment

The controls below describe the protections in place today and the outcomes they provide for institutional clients.

01

Client data isolation

Documents, analysis and results are isolated by organisation and deal. Enforced controls prevent access across client environments.

02

Private analysis infrastructure

Analysis processing and data stores operate within private infrastructure and are not directly exposed to the public internet.

03

Identity and access controls

Access is restricted to authenticated users and the organisations and deals they are authorised to review.

04

Encryption

Client data is encrypted in transit and at rest across the underlying cloud infrastructure.

Data governance

Customer information remains controlled, reviewable and separate

Auditability

A reviewable decision record

Source documents, analysis and results remain connected within the client environment, supporting traceability from evidence to the investment conclusion.

Model usage

No customer-data training

Client documents and PEVio analysis are not used to train third-party AI models. Relevant services are configured against training on submitted content.

Retention and deletion

Deletion includes derived analysis data

When a document is removed from a deal, its records, indexed content and derived copies created for analysis are deleted from the PEVio analysis store.

Current service providers

A controlled provider environment

Only services required to operate the platform process relevant client information. Their terms and configuration are reviewed against the PEVio customer-data policy.

Cloud infrastructure

Private processing, data storage and managed platform services.

Specialised AI services

Controlled processing services configured so submitted customer data is not used for model training.

Security diligence, reviewed 9 September 2026

Evidence for institutional review

A review begins with the security overview: where data is hosted and in which region, how tenants are isolated, how access is controlled and how long data is retained. The sub-processor register sits alongside it, naming each provider and the transfer mechanism that covers it.

Detailed control information and supporting materials can be made available to prospective institutional clients through a structured diligence process and, where appropriate, under NDA.

Confidential conversation

Discuss security within your diligence process

Review the controls, deployment requirements and governance questions relevant to your institution in a confidential conversation.

Request a walkthrough