Governance policy

Cybersecurity Policy


The firm’s safeguards for protecting information systems, investor data, and fund operations against cyber threats.

← Governance

Policy OwnerChief Compliance Officer
Approving BodyBoard of Managers
Effective DateJanuary 1, 2026
Last ReviewedJanuary 1, 2026
Next ReviewJanuary 1, 2027
Version1.0

1. Purpose

This policy establishes the firm’s information-security program to protect the confidentiality, integrity, and availability of its systems and data, consistent with Regulation S-P and applicable data-protection laws.

2. Scope

The policy applies to all personnel, systems, devices, and third parties that access firm or fund information.

3. Governance

The Chief Compliance Officer, together with information-technology leadership, oversees the program, reports to senior management, and reviews the program at least annually.

4. Access Controls

Access to systems and data is granted on a least-privilege basis, protected by multi-factor authentication, and reviewed periodically. Access is revoked promptly upon role change or departure.

5. Data Protection

Sensitive data is encrypted in transit and at rest. Investor personal information is handled consistent with the firm’s Privacy Policy and Regulation S-P.

6. Threat Management

The firm employs endpoint protection, network monitoring, patch management, and email-security controls, and conducts periodic vulnerability assessments and penetration testing.

7. Vendor & Service-Provider Risk

Third parties with access to firm data, including the fund administrator and custodian, are subject to security due diligence and contractual safeguards.

8. Incident Response

The firm maintains an incident-response plan covering detection, containment, eradication, recovery, notification, and post-incident review. Material incidents are reported to affected parties and regulators as required by law.

9. Training & Awareness

Personnel receive security-awareness training at hire and periodically, including phishing simulations and reporting procedures.

10. Testing & Review

The program and incident-response plan are tested periodically and updated to reflect the evolving threat environment.

Notice

This document is a summary of the firm’s internal policy as adopted by the approving body identified above. The complete policy as adopted governs in any case of conflict between this summary and the underlying policy document. Limited partners and other authorized parties may request the full policy from the policy owner. This document does not create contractual rights, employment rights, or third-party beneficiary rights, and may be amended at any time by action of the approving body.

Questions about this policy should be directed to [email protected]. Confidential or anonymous reports may also be made through the channels described in the Whistleblower Policy.

Questions about firm governance

Limited partners, regulators, and counterparties with questions about firm governance, policies, or compliance should contact [email protected].