Access control
Permissions are set per role and per mandate. A user sees the relationships assigned to them, and nothing else. Administrative rights are separate from data-entry rights.
A reporting platform earns its place by producing figures that survive scrutiny. That requires two things: keeping the data safe, and keeping the chain from raw record to published number unbroken.
Permissions are set per role and per mandate. A user sees the relationships assigned to them, and nothing else. Administrative rights are separate from data-entry rights.
Traffic is encrypted in transit. Stored data is encrypted at rest and backed up on a regular schedule, with restores tested rather than assumed.
Positions, prices, valuations, overrides and released reports are versioned. Records are added, never silently rewritten — the previous state stays retrievable.
Most reporting errors are not malicious; they are unreviewed. AAM makes the review step structural rather than optional.
Valuations are reproducible as of their own date. A report run today for a period two years ago returns the figures published then, not today's restated view — unless a restatement was explicitly recorded.
The clearest security statement a software vendor can make is an honest account of the risks it does not carry on your behalf.
Your assets stay with your banks, brokers and custodians. The platform reads records; it does not hold money or securities, and cannot move them.
Rebalancing produces a proposed order list for human release and export. Routing and execution remain with your venue, under your own arrangements.
The platform measures and reports. It makes no recommendation about instruments, allocations or managers, and issues no forecasts.
Records are exportable in open formats at any point in the relationship, including at the end of it. There is no exit fee for taking your own data with you.
Hosting region is agreed per engagement, taking account of where your entity is domiciled and any data-residency requirement that applies to it. The chosen region, provider and backup arrangement are stated in the service agreement rather than left to a general policy page.
Access by our staff is limited to what a specific support or onboarding task requires, granted for the duration of that task, and logged. Where you prefer that we hold no standing access at all, that can be configured — with the trade-off that support requests then need you to reproduce the issue or grant temporary access.
You receive a full export of positions, transactions, valuations and released reports in open formats (CSV and PDF), together with the documentation needed to read them. Retention and deletion of the remaining copies follow the schedule set out in the service agreement.
Affected clients are notified directly, with what is known at the time, what is not yet known, and what we are doing about it — followed by a written account once the picture is complete. Notification timelines are set out in the service agreement.
We do not claim certifications we do not hold. If your procurement process requires a specific standard or an independent assurance report, tell us at the outset and we will tell you plainly what we can and cannot evidence today.
Security questionnaires welcome. If your compliance team has a standard questionnaire, send it with your enquiry and we will complete it as part of the evaluation rather than after it.
It is cheaper for both of us to find a blocker during evaluation than during onboarding.