Cybersecurity Policy | TetraHomes
Cybersecurity Policy.
Protection of firm and investor data, access controls, and incident response.
Program overview.
TetraHomes maintains a cybersecurity program aligned with the NIST Cybersecurity Framework, including governance, identification, protection, detection, response, and recovery.
Access controls.
Access to firm systems is granted on a least-privilege basis. Multi-factor authentication is required for all remote access and privileged accounts.
Data protection.
Personally identifiable information and confidential fund data are encrypted in transit and at rest. Data retention and destruction schedules are enforced.
Vendor management.
Third-party service providers with access to firm data undergo cybersecurity due diligence and are subject to contractual security requirements.
Incident response.
The firm maintains a written incident response plan with defined roles, notification procedures, and post-incident review.
Training.
All employees complete annual cybersecurity training and periodic phishing simulations.
This policy is provided for informational and disclosure purposes. It may be amended from time to time. For the current version, contact [email protected].