Cybersecurity Policy
The firm's framework for protecting the confidentiality, integrity, and availability of information assets, including limited partner data, portfolio-company data, firm intellectual property, and operating systems.
- Policy Owner
- Chief Technology Officer & Chief Information Security Officer
- Approving Body
- Audit Committee
- Effective Date
- January 1, 2026
- Last Reviewed
- June 1, 2026
- Next Review
- January 1, 2027
- Version
- 1.0
Purpose
The Cybersecurity Policy establishes the firm's framework for protecting the confidentiality, integrity, and availability of the firm's information assets, including limited partner data, portfolio company data, firm intellectual property, and operating systems. The Policy reflects the firm's recognition that cybersecurity is a fiduciary obligation owed to limited partners and a regulatory obligation under the Investment Advisers Act, state breach notification laws, and emerging federal cybersecurity rules.
Scope
This Policy applies to all Personnel and to all information assets owned, licensed, processed, or controlled by the firm, including on-premise systems, cloud services, endpoint devices, portable storage, mobile devices, and third-party managed services.
Governance
Cybersecurity is governed by the Chief Technology Officer, serving concurrently as Chief Information Security Officer, reporting to the Chief Executive Officer with a dotted-line reporting relationship to the Audit Committee. The Audit Committee reviews the cybersecurity program on a quarterly basis.
Risk Assessment
The firm conducts an annual enterprise cybersecurity risk assessment covering people, process, and technology. Assessment findings inform the annual cybersecurity roadmap, budget, and risk-tolerance calibration.
Access Controls
Access to firm systems is granted on a least-privilege, need-to-know basis. Multi-factor authentication is required for all Personnel, all limited partner portal access, and all administrative access. Privileged access is subject to just-in-time provisioning and session recording.
Encryption
Limited partner data, portfolio company data, and firm confidential information are encrypted at rest and in transit using industry-standard algorithms. Encryption keys are managed under a dedicated key-management system with separation of duties.
Vulnerability Management
The firm scans for vulnerabilities on a rolling schedule and remediates critical vulnerabilities within seven days and high vulnerabilities within thirty days. External penetration testing is performed at least annually by an independent qualified firm.
Endpoint and Email Security
All endpoints are subject to endpoint detection and response, disk encryption, and mobile device management. Email is protected by anti-phishing, anti-malware, and data loss prevention controls, with executive-impersonation and business-email-compromise protections.
Third-Party Risk
The firm assesses the cybersecurity posture of third parties handling firm or limited partner data at onboarding and on a recurring basis. Material third-party incidents are treated as firm incidents for reporting purposes.
Incident Response
The firm maintains a written incident response plan, tested at least annually through tabletop exercises. Confirmed material cybersecurity incidents are reported to the Chief Executive Officer within four hours, to the Audit Committee within 24 hours, and to limited partners and regulators as required by applicable law.
Training and Culture
All Personnel receive cybersecurity training at onboarding, annually, and following any material incident. Simulated phishing exercises are conducted at least quarterly.
Independent Assessment
An independent third party performs a comprehensive cybersecurity assessment at least every two years. Findings are reported to the Audit Committee and remediation is tracked to closure.
