Minimal intake
Public forms ask for only identity, contact, public profile or firm page, and primary jurisdiction. Sensitive facts wait until a private channel and NDA.
Security and diligence
HNWI Chronicles uses controlled access, data minimization, case separation, and confidentiality-first workflows. No SOC 2, ISO 27001, PCI DSS, or equivalent third-party certification is publicly asserted without auditor evidence.
Last reviewed July 12, 2026.
Public forms ask for only identity, contact, public profile or firm page, and primary jurisdiction. Sensitive facts wait until a private channel and NDA.
Submissions and materials are handled on a need-to-know basis with internal access narrowed to the work required.
Public archive content, fit review data, and private engagement materials are treated as separate surfaces.
The public site and app are delivered through Vercel. Core Kingdom and Granthika services operate on AWS in ap-south-1, with Cloudflare used for DNS and controlled service routing. Global delivery and named processors may process data outside India; no single-region guarantee is made unless agreed in writing.
Current operating providers may include Vercel, AWS, Cloudflare, Google, Microsoft Clarity, Meta, Calendly, and Razorpay, each limited to the function for which it is enabled.
Private context is not turned into public proof without consent and redaction.
Public intake, engagement, billing, and security records are retained only for the operating, contractual, legal, and security need. A case-specific schedule may be agreed for a private engagement.
If a security concern arises, the operating priority is containment, access review, evidence preservation, and controlled communication.
Attestation status
We do not claim SOC 2, ISO 27001, PCI DSS, GDPR certification, or any equivalent third-party attestation without a current auditor-issued scope. Architecture controls and operating discipline are described as controls, not certifications.
Security contact
Email hnwi@montaigne.co with the subject “Security report”, or use the confidential fit review path. Do not include sensitive client documents, credentials, or exploit data in the first public submission.