Security Overview
This overview summarises the technical and organisational measures protecting data processed by Grant Fund LLC. It is written for prospective customers, investors and due-diligence reviewers, and supplements our Privacy Policy and Data Processing Addendum.
1. Measures
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These include access controls, authentication controls, role-based permissions, encryption in transit, least-privilege access, logging and monitoring, backup procedures, internal confidentiality obligations, vendor controls, incident response procedures, and security review of subprocessors.
2. Hosting
The Service is hosted in the EU/EEA. The operator is incorporated in Delaware, United States, so our own access to data stored in the EEA is itself a transfer; how transfers are handled is described in Privacy Policy §10, and our infrastructure providers and other subprocessors and their locations are listed in our Subprocessor List.
3. Shared responsibility
No online service can guarantee absolute security. Users are responsible for maintaining secure credentials, managing internal access, controlling what they upload, and notifying us of a suspected compromise. Deciding which sensitive business or technical information is appropriate to submit to the Service remains the User's call.
4. Sensitive technical information
For deeptech companies we specifically recommend care with unpublished patent claims, trade secrets, source code, confidential R&D information, export-controlled material, and other highly sensitive technical information. The screen does not need them: it compares published programme conditions against structured company facts, and a description of what a technology does is enough for that.
Do not send material of this kind through our support channels or by ordinary email. Where sensitive material is genuinely required to investigate an issue, we will arrange an appropriate channel separately.
5. Certifications
We do not hold ISO 27001, SOC 2, or comparable certification, and we make no claim to any. Should we obtain one, it will be stated here with its scope and date; until then, statements to the contrary from any source are not authorised.
6. Reporting a vulnerability
Report suspected vulnerabilities or security incidents to security@grant.fund. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to respond before any public disclosure.
Questions about your data?
For any privacy request or question, contact us at privacy@grant.fund.
Data Protection Officer / EU representative: Ivan Petrakov

