Cybersecurity Policy
Access control, incident response, and vendor security.
Effective: January 1, 2026 · Reviewed annually by the Chief Compliance Officer
The Aukeo Cybersecurity Policy governs the confidentiality, integrity, and availability of firm and LP data. The policy applies to all firm personnel, contractors, and vendors with access to firm systems and is administered by the firm's technology and compliance functions.
Access control
Access to firm systems is provisioned on a least-privilege basis, subject to multi-factor authentication for all users. Elevated privileges are logged, reviewed quarterly, and revoked upon role change or departure.
Incident response
The firm maintains a written incident-response plan covering detection, containment, eradication, recovery, and post-incident review. Material incidents are reported to the CEO and, where applicable, to the Audit Committee and affected LPs.
Vendor security
All vendors with access to firm data undergo a written security review prior to onboarding and annually thereafter. Fund administrator, auditor, and other critical vendors are held to defined security standards.
Data classification and retention
Firm data is classified by sensitivity and retained under a written retention schedule aligned to regulatory and LP contractual requirements.
Questions regarding this policy may be directed to the Chief Compliance Officer at [email protected].
