Security at Cura

Cura handles sensitive portfolio and investment data. Here's how we protect it.

Last updated May 20, 2026

Infrastructure

Cura runs on SOC 2 Type II providers. Workspaces are isolated, and production access is least-privilege.

Encryption and isolation

Traffic to Cura uses TLS 1.2 or higher, and customer data is encrypted at rest. Each customer runs in an isolated environment, so there's no cross-tenant access.

Backups are encrypted, stored across multiple regions, and retained for 30 days. If you ask us to delete your data, we remove it from production within 30 days and purge it from backups within 90.

We don't train AI on your data

Cura doesn't train AI on customer data, and neither do our AI providers. OpenAI and Anthropic both contractually agree not to use API inputs or outputs for training.

Policies

For the providers we use and our legal commitments:

Contact

Questions about our security practices, or need documentation for a review? Reach out to sharan@cura.inc.