Security at Cura
Cura handles sensitive portfolio and investment data. Here's how we protect it.
Last updated September 2, 2026
Certifications
We're pursuing SOC 2 Type II certification. If you need a letter of engagement for your own review, reach out and we can provide one.
Infrastructure
Cura runs on SOC 2 Type II providers. Workspaces are isolated, and production access is least-privilege.
Encryption and isolation
Traffic to Cura uses TLS 1.2 or higher, and customer data is encrypted at rest. Each customer runs in an isolated environment, so there's no cross-tenant access.
Backups are encrypted, stored across multiple regions, and retained for 30 days. If you ask us to delete your data, we remove it from production within 30 days and purge it from backups within 90.
We don't train AI on your data
Cura doesn't train AI on customer data, and neither do our AI providers. OpenAI and Anthropic both contractually agree not to use API inputs or outputs for training.
Policies
For the providers we use and our legal commitments:
- Sub-processors — The third parties we use to run Cura.
- Privacy Policy — How we handle personal data, including data we process for customers.
- Terms of Service — The terms that govern your use of Cura.
Contact
Questions about our security practices, or need documentation for a review? Reach out to sharan@cura.inc.