Policies
Keel maintains the following policies governing data, security, and access. Publicly available policies are linked below. Internal policies are listed by title and made available to limited partners, regulators, and audit counterparties on request.
Public Policies
- Privacy PolicyDraft
Describes what personal information we collect from limited partners and prospects, how we use and share it (including bank data via Plaid), retention periods, and your rights. Published in draft and subject to change pending legal counsel review.
- Terms of ServiceDraft
The terms governing access to and use of the firm's websites, portals, and fund-administration software. Published in draft pending legal counsel review.
- Cookie NoticeDraft
How we use cookies and similar technologies — primarily strictly-necessary authentication and security cookies, with no cross-site advertising tracking.
How we use Plaid to connect financial accounts, what data is accessed for reconciliation, how it is protected, and how to revoke access.
Platform Security & Operations Policies
The following policies govern how the platform is built, secured, and operated. They are maintained by Keel, the software platform powering this portal, and apply to every fund on it. Click any policy to read it in full and download a PDF for your LPs, regulators, or audit counterparties.
- Information Security PolicyDraft
Master security policy governing data classification, secure development, incident response, vendor management, cryptography, and business continuity.
- Patch SLA PolicyDraft
Time-to-patch service levels by vulnerability severity (Critical 7 days / High 30 / Medium 90 / Low 180), supported by automated dependency scanning.
- EOL Software Management PolicyDraft
Six-month dependency inventory, vendor end-of-life monitoring, upgrade-vs-replace decision criteria, and documented exception handling.
- Access Control PolicyDraft
Role-based access tiers, written request workflow, off-boarding checklist, quarterly access reviews, and audit-event capture for all administrative actions.
- Data Retention and Deletion PolicyDraft
Retention periods by record category, deletion procedures, limited-partner-initiated deletion request handling, and vendor data deletion propagation.
Compliance & Attestations
The firm maintains compliance with applicable financial-services regulations governing private fund advisers. We are in active progress toward formal attestations with our data partners, including Plaid. Detailed compliance information is available on request.