πŸ”’
Security & Trust Center

Enterprise-grade protection for your retirement plan data

βœ“

All Systems Secure

Your data is protected with enterprise-grade security and never used for AI training.

πŸ”Œ API-First Architecture β€” Not a Chatbot

Fund(k) connects to Anthropic's enterprise API, not consumer chatbots. Your data is never used for training, never stored in shared conversation logs, and never reviewed by humans. Fund scoring data comes from SEC EDGAR and Yahoo Finance β€” public, verifiable sources only.

How Your Data is Protected
πŸ“„
Your CSV
β†’
πŸ–₯️
Browser
β†’
πŸ”
TLS 1.3
β†’
☁️
Cloudflare
β†’
πŸ“Š
Scores
β†’
πŸ—‘οΈ
Auto-Delete
Core Security Features
🚫
Zero Training Guarantee
Anthropic's enterprise API never uses your inputs or outputs to train models. Contractually guaranteed.
πŸ”
End-to-End Encryption
AES-256 at rest, TLS 1.3 in transit. Data encrypted at every stage via Cloudflare's edge network.
⏱️
Zero Data Retention
Anthropic offers Zero Data Retention (ZDR). AI queries are processed and immediately discarded β€” nothing stored.
πŸ‘οΈβ€πŸ—¨οΈ
No Human Review
Unlike consumer chatbots, enterprise API data is never reviewed by humans at Anthropic.
Compliance Certifications
πŸ†
SOC 2Type II Certified
🌐
ISO 27001Information Security
πŸ₯
HIPAABAA Available
πŸ‡ͺπŸ‡Ί
GDPRCompliant
πŸ‡ΊπŸ‡Έ
CCPACompliant
πŸ’‘ Tip: See the Compliance tab for detailed regulatory alignment information.

Fund(k) uses Anthropic's enterprise Claude API exclusively. Your data is never used for training and has strict retention limits.

Consumer Chatbot vs. Enterprise API
Security AspectConsumer ChatbotsEnterprise API (What We Use)
Training on your data❌ May train on conversationsβœ“ NEVER trains on your data
Data retention❌ Stored indefinitelyβœ“ Zero Data Retention available
Human review❌ May review for qualityβœ“ No human review of content
Privacy policies❌ Consumer privacy termsβœ“ Enterprise DPA / BAA available
Compliance❌ Limited certificationsβœ“ SOC 2, ISO 27001, HIPAA-ready
Our AI Provider
Claude

Anthropic Claude

Claude Opus 4.6 API
SOC 2 Type II ISO 27001 HIPAA
  • Zero Data Retention (ZDR) option
  • No training on API data β€” ever
  • 30-day max retention (without ZDR)
  • Enterprise DPA available
  • Used for AI chat assistant only β€” scoring is algorithmic
πŸ’‘ Note: Fund(k) scores are calculated entirely algorithmically from SEC and Yahoo Finance data. The AI assistant is optional and only used for conversational queries about fund data β€” it does not influence scores.
πŸ”„ How Your Data Flows

Understanding exactly what data is sent where gives you confidence in our security architecture.

Fund(k) Secure Processing Pipeline
πŸ“„
Your CSV
Ticker + assets
β†’
πŸ–₯️
Browser
Parse locally
πŸ”’β†’
☁️
Cloudflare
D1 + Workers
πŸ”’β†’
πŸ“Š
Fund Scores
Pre-computed
β†’
πŸ“ˆ
Analysis
In your browser
πŸ“¦ What Data Is Sent
βœ…
Ticker Symbols Only
Portfolio uploads send only fund tickers to our API. Pre-computed scores are returned. No participant data, no plan sponsor info.
πŸ”
Encrypted in Transit
All data uses TLS 1.3 encryption between your browser and Cloudflare's edge network.
πŸ“Š
Pre-Computed Scores
Fund scores are computed offline from SEC/Yahoo data and stored in Cloudflare D1. No real-time AI processing of your fund data.
πŸ—‘οΈ
Nothing Stored
Your portfolio CSV is parsed in-browser and never uploaded to any server. Analysis happens entirely client-side.
⚠️ Important: Your CSV file is parsed locally in your browser. Only ticker symbols are sent to our API to retrieve pre-computed scores. No files are uploaded or stored.
βš–οΈ Regulatory Compliance
βš–οΈ
ERISA
Designed for fiduciary compliance. 100% quantitative scoring supports prudent process documentation. No conflicts of interest or proprietary fund bias.
πŸ›οΈ
DOL Fiduciary Rule
Transparent methodology and reproducible scores align with DOL's emphasis on documented, objective investment monitoring processes.
πŸ“‹
DOL Cybersecurity
Aligned with DOL's cybersecurity guidance for plan fiduciaries. Encryption, access controls, and incident response documented.
πŸ‡ͺπŸ‡Ί
GDPR
Data minimization by design. No PII collected. No unnecessary retention. Clear data processing purposes.
βœ… Security Controls Implemented

πŸ” Fund(k) Security Checklist

βœ“ No PII collected or stored
βœ“ Encrypted transmission (TLS 1.3)
βœ“ No AI training on plan data
βœ“ SOC 2 Type II certified providers
βœ“ Zero revenue sharing influence
βœ“ Open, reproducible methodology
πŸ“„ Documentation: For fiduciary due diligence, SOC 2 reports are available under NDA from Anthropic's trust center.
❓ Frequently Asked Questions

No. Fund(k) uses Anthropic's enterprise API tier. API data is NOT used to train models. Contractually guaranteed. Additionally, fund scores are computed offline β€” AI is only used for the optional chat assistant.

Your portfolio CSV is parsed in-browser and never uploaded. Only ticker lookups hit our API. AI chat queries use Anthropic's Zero Data Retention β€” processed and immediately discarded.

No. Enterprise API data is NOT subject to human review. Only automated systems process the data briefly before deletion.

None. Fund(k) only works with fund-level data (tickers, expense ratios, returns). No participant SSNs, names, balances, or any PII is ever collected, processed, or stored.

Scores are computed offline using a Python pipeline that pulls data from SEC Form N-PORT and Yahoo Finance. Pre-computed scores are stored in Cloudflare D1 and served via API. No real-time AI is involved in scoring.

Yes. Fund(k) receives zero revenue sharing, has no fund company partnerships, no proprietary fund preferences, and no qualitative overrides. All 1,624 funds are scored identically using the same 20 quantitative metrics. See the Conflict-Free Commitment in the sidebar for details.

Anthropic: SOC 2 Type II, ISO 27001, HIPAA BAA available. Cloudflare (infrastructure): SOC 2 Type II, ISO 27001, PCI DSS Level 1, FedRAMP.

πŸ”— Anthropic Trust πŸ”— Cloudflare Trust