← Governance
Governance policy

Cybersecurity Policy

The firm's framework for protecting the confidentiality, integrity, and availability of information assets, including limited partner data, portfolio-company data, firm intellectual property, and operating systems.

Policy Owner
Chief Technology Officer & Chief Information Security Officer
Approving Body
Audit Committee
Effective Date
January 1, 2026
Last Reviewed
June 1, 2026
Next Review
January 1, 2027
Version
1.0

Purpose

The Cybersecurity Policy establishes the firm's framework for protecting the confidentiality, integrity, and availability of the firm's information assets, including limited partner data, portfolio company data, firm intellectual property, and operating systems. The Policy reflects the firm's recognition that cybersecurity is a fiduciary obligation owed to limited partners and a regulatory obligation under the Investment Advisers Act, state breach notification laws, and emerging federal cybersecurity rules.

Scope

This Policy applies to all Personnel and to all information assets owned, licensed, processed, or controlled by the firm, including on-premise systems, cloud services, endpoint devices, portable storage, mobile devices, and third-party managed services.

Governance

Cybersecurity is governed by the Chief Technology Officer, serving concurrently as Chief Information Security Officer, reporting to the Chief Executive Officer with a dotted-line reporting relationship to the Audit Committee. The Audit Committee reviews the cybersecurity program on a quarterly basis.

Risk Assessment

The firm conducts an annual enterprise cybersecurity risk assessment covering people, process, and technology. Assessment findings inform the annual cybersecurity roadmap, budget, and risk-tolerance calibration.

Access Controls

Access to firm systems is granted on a least-privilege, need-to-know basis. Multi-factor authentication is required for all Personnel, all limited partner portal access, and all administrative access. Privileged access is subject to just-in-time provisioning and session recording.

Encryption

Limited partner data, portfolio company data, and firm confidential information are encrypted at rest and in transit using industry-standard algorithms. Encryption keys are managed under a dedicated key-management system with separation of duties.

Vulnerability Management

The firm scans for vulnerabilities on a rolling schedule and remediates critical vulnerabilities within seven days and high vulnerabilities within thirty days. External penetration testing is performed at least annually by an independent qualified firm.

Endpoint and Email Security

All endpoints are subject to endpoint detection and response, disk encryption, and mobile device management. Email is protected by anti-phishing, anti-malware, and data loss prevention controls, with executive-impersonation and business-email-compromise protections.

Third-Party Risk

The firm assesses the cybersecurity posture of third parties handling firm or limited partner data at onboarding and on a recurring basis. Material third-party incidents are treated as firm incidents for reporting purposes.

Incident Response

The firm maintains a written incident response plan, tested at least annually through tabletop exercises. Confirmed material cybersecurity incidents are reported to the Chief Executive Officer within four hours, to the Audit Committee within 24 hours, and to limited partners and regulators as required by applicable law.

Training and Culture

All Personnel receive cybersecurity training at onboarding, annually, and following any material incident. Simulated phishing exercises are conducted at least quarterly.

Independent Assessment

An independent third party performs a comprehensive cybersecurity assessment at least every two years. Findings are reported to the Audit Committee and remediation is tracked to closure.