Trust / Security

Security is part of the work.

Funds and founders use Anker to hold sensitive material: pitch decks, LP letters, cap tables, and capital calls. Explore the practices behind the platform.

Practices

Protecting the information behind your decisions.

Account protection

Anker’s account system uses hashed passwords and signed sessions. Restricted workflows check the signed-in user before granting access.

Administrative controls

Administrative tools use server-side access checks. Fund operations and publishing workflows have dedicated access controls.

Activity records

Audit records support review of recorded administrative activity, including the actor, action, and timestamp. Ask us about coverage and retention for your workflow.

LP access

LP portal access is scoped to an investor and fund. Portal links can be revoked and can carry an expiry date.

Review before publishing

LP reports and letters pass through publication states before they become available in the portal. Teams control what they share with investors.

Deployment requirements

Encryption, backups, retention, and AI provider settings depend on the deployment. Contact us to review the configuration and requirements for your organization.

Responsible disclosure

Find a vulnerability?

Email security@an-ker.de with a description and steps to reproduce. Include the affected page or workflow and use a minimal example that does not expose another person’s information.

  • · Do not exfiltrate data — a single proof-of-access is enough
  • · Do not access other users' accounts without explicit permission
  • · Do not perform DoS or social engineering
  • · Give us a reasonable window to fix before public disclosure
Incident response

Discuss your response requirements.

Contact our security team to discuss incident handling, notification arrangements, and the documentation your organization needs before sharing sensitive material.

Questions?

For security documentation and data-processing questions, email security@an-ker.de.