Skip to content

Security & trust

Precise about what we are, and what we are not.

Fund OS is a software tool used by regulated firms. Regonance is not a regulated entity and provides no fund, legal, tax or advisory services. Everything below describes how the software is built and operated — not a regulatory status, and not an approval.

Data handling

Where data lives and how it moves.

EU hosting

Customer data is hosted within the European Union, with no default transfer outside it. The full hosting and sub-processor list is provided on request as part of diligence.

Encryption

Data is encrypted in transit and at rest, with keys managed by the hosting platform. Cipher and key-management detail is shared under diligence.

Segregation

Each organisation's workspace is logically separated, and access between organisations exists only where an engagement has been proposed and accepted.

Retention and deletion

Records are retained for the life of the engagement and handled on exit per contract, including an export of your fund records before deletion.

GDPR posture

Built around GDPR principles.

Fund OS is designed and operated in line with GDPR data-protection principles. Personal data on the platform is largely professional contact and action data — who at which firm did what — and the model is kept deliberately narrow.

Data minimisation

Only the personal data needed to attribute an action and route a request is collected.

Purpose limitation

Data is used to operate the coordination service, not resold, profiled or repurposed.

Subject rights

Access, rectification and erasure requests are supported, balanced against the record-keeping obligations of the customer firms. Regonance acts as processor for customer data; a data-processing agreement is provided with the beta agreement.

Architecture

Why the record can be trusted.

  • Event-sourced core: state is derived from a sequence of recorded events.
  • Append-only history — corrections are new events, not silent rewrites.
  • Row-level access control enforced in the data layer, not only in the interface.
  • Every action attributed to a named user acting for a named organisation.
  • Authentication with per-organisation membership and role-based permissions.

Assurance and certifications

We describe only what exists. Where an external assurance standard is relevant, it will be named here once achieved and evidenced — not before.

Regonance holds no external security certification today, and we do not imply one. Formal assurance work is planned as the customer base grows, and will be named here only once completed.

Regulatory positioning

What we will and will not claim.

We say

  • Designed for firms operating in the Luxembourg fund framework.
  • Built around delegation, documentation and oversight practice.
  • Aligned with GDPR data-protection principles.
  • Supports your own record-keeping and oversight obligations.

We never say

  • That the software is approved by any regulator.
  • That using it makes a firm or a fund compliant.
  • That anything on the platform is certified or validated.
  • That Regonance performs any regulated or advisory function.

Our privacy policy, terms of service and data-processing agreement are issued with the beta agreement and are available on request at hello@regonance.com.

FAQ

Security questions we are asked in diligence.

Where is Fund OS data hosted?

Within the European Union. There is no default transfer of customer data outside the EU.

Is Regonance a regulated entity?

No. Regonance is a software provider. It holds no licence, is not a regulated entity, and provides no fund, legal, tax or advisory services. Regulatory responsibility remains with the licensed firms using the software.

How does Fund OS relate to the Luxembourg regulatory framework?

Fund OS is designed for firms operating under that framework. Its workflow and record-keeping model is built around the documentation, delegation and oversight practices those firms already maintain. It does not certify, validate or approve anything, and it is not a substitute for a firm's own control framework.

Who can see our data?

Access follows the engagement. An organisation reaches only the funds and requests it has been engaged on, in the role it accepted. Counterparties on the same fund are isolated from one another unless the workflow explicitly involves both.

Can we export our records?

Yes. The audit trail and fund records are exportable so they can be used in internal review, board reporting and provider oversight files.

Send us your diligence questionnaire

We would rather answer your security and data-protection questions early than late. Send the questionnaire you use and we will complete it.