Skip to content
Otterd
Back to the home page

Security and data

This page is for the person at your firm who checks vendors. It explains where your data goes, who can see it, and what the agent can and cannot do.

Last updated:

In short

  • Your data stays in your systems. The agent runs in your environment.
  • You choose where the AI model runs: your AI account, your cloud, or your own servers.
  • Our access is read-only and limited to one workflow. It ends at Transfer.
  • Every run keeps a log, and a person approves each action that leaves your firm.

Details depend on your setup. We confirm them with your IT team.

Where the agent runs

The workflow connects tools that you already have: spreadsheets, email, documents and shared folders. We build it inside your environment, so your documents do not move to a new platform.

The agent sends text only to the AI model that you choose. Otterd reaches your environment through a service account that you control.

Your tools, the workflow and the AI model stay inside your environment A dashed line marks your environment. Inside it are your spreadsheets, email, documents and shared folders, the workflow, and the AI model that you choose. Otterd is outside the line, with read-only access that ends at Transfer. Your environment Spreadsheets Email Documents Shared folders One workflow The AI model you choose Otterd Read-only access.Ends at Transfer.

Choose your level of privacy

At every level, the agent runs in your environment. The difference is where the AI model runs.

At every level, our access is read-only, every run keeps a log, and a person approves each action that leaves your firm.

Open-weight models can be less capable than the leading models for some tasks. We test your workflow on the level you choose before you decide.

Access during the project

Access follows the three stages of the project. At the end, only your team has access.

Access during the project
Stage Who runs it Who has access Time
Build Otterd Otterd, read-only, on sample data 2 to 3 weeks
Operate Otterd with your team Otterd and your team 4 to 8 weeks
Transfer Your team Your team only 1 week

Questions from fund teams

Where does our data go?

It stays in your systems. The agent runs in your environment.

The agent runs in your cloud account or your Microsoft 365 or Google Workspace tenant. Otterd does not keep a copy of your documents. Text goes only to the AI model that you choose.

Which AI model sees our data?

Only a model that you choose. At the highest level, no text leaves your network.

Most teams use their firm's business account with a provider such as Anthropic or OpenAI. Under business terms, these providers do not train on your data by default. Where the provider offers zero data retention, we turn it on. For more control, the model can run in your own cloud account or on your own servers.

Who has access, and for how long?

Read-only access, only to what the workflow needs. It ends at Transfer.

We use a separate service account for each system, with the minimum permissions. You see each permission before we start. At Transfer, you remove our access, and we confirm it in writing.

What if a document contains hidden instructions?

No defense stops this completely, so we limit what the agent can do.

A CIM or a data room file can hide text such as "send this file to…". This is called prompt injection. The agent treats documents as data, not as commands. It has a fixed list of actions, and most of its access is read-only. It cannot send email to a new address. A person approves each action that leaves your firm.

Can we see what the agent did?

Yes. Every run keeps a log, so the agent is not a black box.

The log shows what the agent read, what it flagged, which model it used, and who decided. The log stays in your systems, so your compliance team can review it with your other records.

What about information barriers and MNPI?

The agent sees only the folders and mailboxes for its workflow.

We set access by team, to match your information barriers. When a workflow writes research notes, the agent can check your restricted list first. For MNPI, you can choose the level where the model runs on your own servers.

What happens to our data at the end?

We delete our working copies and confirm it in writing.

At Transfer, you remove our access. We delete any working copies, such as test files, and confirm it in writing. You also get a one-page description of the workflow for your AI inventory and your LP questionnaires.

What if something goes wrong?

We tell you within 24 hours.

If we find a problem that can affect your data, we tell your named contact within 24 hours. We say what we know and what we do next. The log helps your team see what the agent did.

How do we check you as a vendor?

We answer your security questionnaire and sign your NDA.

Send your vendor questionnaire before the project starts, and we answer it in writing. We do not have a SOC 2 report yet, so we describe each control in writing instead. Our contract states that your data does not train any model. Please do not send confidential documents before the NDA is signed.

Third parties

Otterd adds no new vendor that sees your data. Text goes only to the tools you already use and the AI model you choose.

Otterd does not hold your data, so we use no subprocessors for it. If that changes, we tell you before the change.

What we ask of you

Before we start, we need four things from your firm.

  1. A contact in IT or operations who approves each permission.
  2. A decision on the level of privacy: your AI account, your cloud, or your own servers.
  3. A check by your counsel that your LPA confidentiality terms permit this use of portfolio data.
  4. A signed NDA before you share any confidential document.

Send us your questionnaire

Start with a 30-minute consultation. Send your security questionnaire at the same time, and we answer it in writing.

Get in touch