Skip to main content
Back to HNWI Chronicles

Security and diligence

Confidential handling is process discipline, not decorative badge copy.

HNWI Chronicles uses controlled access, data minimization, case separation, and confidentiality-first workflows. No SOC 2, ISO 27001, PCI DSS, or equivalent third-party certification is publicly asserted without auditor evidence.

Last reviewed July 12, 2026.

01

Minimal intake

Public forms ask for only identity, contact, public profile or firm page, and primary jurisdiction. Sensitive facts wait until a private channel and NDA.

02

Access discipline

Submissions and materials are handled on a need-to-know basis with internal access narrowed to the work required.

03

Case separation

Public archive content, fit review data, and private engagement materials are treated as separate surfaces.

04

Hosting and processing

The public site and app are delivered through Vercel. Core Kingdom and Granthika services operate on AWS in ap-south-1, with Cloudflare used for DNS and controlled service routing. Global delivery and named processors may process data outside India; no single-region guarantee is made unless agreed in writing.

05

Named service providers

Current operating providers may include Vercel, AWS, Cloudflare, Google, Microsoft Clarity, Meta, Calendly, and Razorpay, each limited to the function for which it is enabled.

06

Redaction before reuse

Private context is not turned into public proof without consent and redaction.

07

Retention boundary

Public intake, engagement, billing, and security records are retained only for the operating, contractual, legal, and security need. A case-specific schedule may be agreed for a private engagement.

08

Containment-first response

If a security concern arises, the operating priority is containment, access review, evidence preservation, and controlled communication.

Attestation status

No badge stands in for an audit.

We do not claim SOC 2, ISO 27001, PCI DSS, GDPR certification, or any equivalent third-party attestation without a current auditor-issued scope. Architecture controls and operating discipline are described as controls, not certifications.

Security contact

Report a concern through a controlled channel.

Email hnwi@montaigne.co with the subject “Security report”, or use the confidential fit review path. Do not include sensitive client documents, credentials, or exploit data in the first public submission.

Open channel