CAPITAL FUSION
Security and data

Read-only first. Nothing happens without an approval on record.

Written for the person who has to say yes to this. Short on adjectives, long on what actually happens.

What we read, in order
Step 0 uses only public information and what you tell us. Step 2 adds one read-only connection or an export you choose. Full access comes last, under a written engagement agreement, and every connection starts read-only.
What we never ingest
Patient-level data. Credentials for systems you did not connect. Anything covered by a data license that does not permit third-party access until that permission is in writing.
Who approves what
Every proposed action is tagged by what it touches: customers, money, public presence, or regulated content. Any of those requires your named partner’s approval and yours. Regulated content also requires your own review process to sign off before use. BEN cannot approve its own actions.
The action log
Every proposal, the evidence behind it, who approved it, when, what was done, and what the result was, in an append-only log you can open with one click. If you ask “what did BEN do to my account,” the answer is a page, not a conversation.
Outside content is treated as data
Web pages, filings, reviews, and emails we read are wrapped and screened before they reach the analysis, and the part of the system that reads outside content has no ability to act. This is how we defend against instructions hidden in things we read.
Where your data lives
Per-client storage, encrypted at rest, with no cross-client context. Connector tokens in a secrets vault, never in the database. Hosting and vendor details are listed in the engagement agreement.

Questions a compliance reader will ask

We would rather answer them here than in a procurement thread.

Does anything get published under my name without me?
No. Outbound and public content requires your approval on record. In regulated settings, your review process approves customer-facing content before use.
Can I revoke access?
Yes, at any step. Read-only connections are revoked on your side; we confirm deletion of derived data in writing.
Who can see my data inside Capital Fusion?
Your named partner and the engineers who operate the system, under the engagement agreement. Never another client, never a model training pipeline.
Is any of this reviewed by a lawyer?
Engagement terms, limitation of liability, and insurance are reviewed by counsel before the first paid engagement. Ask us for the current versions.

Security questions: contact details will be listed here at launch.

The first step asks for nothing.

Ten questions and public information. You connect nothing until the Read has earned it.