Security at Cura
Cura handles sensitive portfolio and investment data. Here's how we protect it.
Last updated May 20, 2026
Infrastructure
Cura runs on SOC 2 Type II providers. Workspaces are isolated, and production access is least-privilege.
Encryption and isolation
Traffic to Cura uses TLS 1.2 or higher, and customer data is encrypted at rest. Each customer runs in an isolated environment, so there's no cross-tenant access.
Backups are encrypted, stored across multiple regions, and retained for 30 days. If you ask us to delete your data, we remove it from production within 30 days and purge it from backups within 90.
We don't train AI on your data
Cura doesn't train AI on customer data, and neither do our AI providers. OpenAI and Anthropic both contractually agree not to use API inputs or outputs for training.
Policies
For the providers we use and our legal commitments:
- Sub-processors — The third parties we use to run Cura.
- Privacy Policy — How we handle personal data, including data we process for customers.
- Terms of Service — The terms that govern your use of Cura.
Contact
Questions about our security practices, or need documentation for a review? Reach out to sharan@cura.inc.