Security at Cura

Cura handles sensitive portfolio and investment data. Here's how we protect it.

Last updated September 2, 2026

Certifications

We're pursuing SOC 2 Type II certification. If you need a letter of engagement for your own review, reach out and we can provide one.

Infrastructure

Cura runs on SOC 2 Type II providers. Workspaces are isolated, and production access is least-privilege.

Encryption and isolation

Traffic to Cura uses TLS 1.2 or higher, and customer data is encrypted at rest. Each customer runs in an isolated environment, so there's no cross-tenant access.

Backups are encrypted, stored across multiple regions, and retained for 30 days. If you ask us to delete your data, we remove it from production within 30 days and purge it from backups within 90.

We don't train AI on your data

Cura doesn't train AI on customer data, and neither do our AI providers. OpenAI and Anthropic both contractually agree not to use API inputs or outputs for training.

Policies

For the providers we use and our legal commitments:

Contact

Questions about our security practices, or need documentation for a review? Reach out to sharan@cura.inc.