Grant Fund
Trust & legal

Security Overview

Last revised August 12, 2026Version 1.1

This overview summarises the technical and organisational measures protecting data processed by Grant Fund LLC. It is written for prospective customers, investors and due-diligence reviewers, and supplements our Privacy Policy and Data Processing Addendum.

1. Measures

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These include access controls, authentication controls, role-based permissions, encryption in transit, least-privilege access, logging and monitoring, backup procedures, internal confidentiality obligations, vendor controls, incident response procedures, and security review of subprocessors.

2. Hosting

The Service is hosted in the EU/EEA. The operator is incorporated in Delaware, United States, so our own access to data stored in the EEA is itself a transfer; how transfers are handled is described in Privacy Policy §10, and our infrastructure providers and other subprocessors and their locations are listed in our Subprocessor List.

3. Shared responsibility

No online service can guarantee absolute security. Users are responsible for maintaining secure credentials, managing internal access, controlling what they upload, and notifying us of a suspected compromise. Deciding which sensitive business or technical information is appropriate to submit to the Service remains the User's call.

4. Sensitive technical information

For deeptech companies we specifically recommend care with unpublished patent claims, trade secrets, source code, confidential R&D information, export-controlled material, and other highly sensitive technical information. The screen does not need them: it compares published programme conditions against structured company facts, and a description of what a technology does is enough for that.

Do not send material of this kind through our support channels or by ordinary email. Where sensitive material is genuinely required to investigate an issue, we will arrange an appropriate channel separately.

5. Certifications

We do not hold ISO 27001, SOC 2, or comparable certification, and we make no claim to any. Should we obtain one, it will be stated here with its scope and date; until then, statements to the contrary from any source are not authorised.

6. Reporting a vulnerability

Report suspected vulnerabilities or security incidents to security@grant.fund. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to respond before any public disclosure.

Questions about your data?

For any privacy request or question, contact us at privacy@grant.fund.

Data Protection Officer / EU representative: Ivan Petrakov

Cookie preferences

We use strictly necessary cookies to run the site, and — only with your consent — analytics and marketing cookies. You can change your choice anytime.