Upside Financial Technologies Inc.

Data Handling & Security Policy

Last updated July 22, 2026 · Contact: hello@upsidepr.ai

This Data Handling and Security Policy (the "Data Policy") forms part of the Upside PR Terms of Service (the "Terms") between Upside Financial Technologies Inc. ("Upside") and the Customer, and is incorporated into the Terms by reference. Capitalized terms not defined here have the meanings in the Terms. It describes what Upside does with Customer Content, the safeguards applied to it, the third parties involved, the retention and deletion schedule, and the risk factors and responsibility allocation that Customer accepts by using the Service. In case of conflict between this Data Policy and the Terms, the Terms govern with respect to liability and remedies, and this Data Policy governs with respect to data handling practices.


1. What Data the Service Handles

1.1 Categories.

1.2 What Upside does with Customer Content. Upside processes Customer Content solely to provide, maintain, secure, and support the Service for Customer, as licensed under the Terms. Specifically, Upside uses draft materials to generate the analysis, comments, rewrites, and redlines Customer requests; uses the corpus to build Customer's baseline report and voice profile; and uses account and usage data to operate, bill, and secure the platform.

1.3 What Upside does not do with Customer Content. Upside does not:

Aggregated, de-identified operational metrics that contain no Customer Content (feature usage counts, latency, error rates) are used to operate and improve the Service.


2. Model Processing Architecture (LLM Handling)

The Service uses large language models. The architecture is designed so that unpublished draft materials are never exposed to a model provider and are never retained by model infrastructure.

2.1 Draft path: in-environment, zero data retention. All processing of draft materials (analyze, comment, rewrite, iterate, and related operations) runs on model infrastructure operating inside Upside's own cloud environment on Amazon Web Services (AWS Bedrock). This path is configured with AWS Bedrock's zero-data-retention control, under which no request or response data is written to durable storage by AWS and none is shared with the model developer. The model developer has no access to this traffic as a matter of platform architecture, not merely contract. Upside verifies at deployment, and monitors on an ongoing basis, that the zero-data-retention mode is in force and that model invocation logging of content is disabled on this path.

2.2 Public-information path. Certain features that require live public-web lookups (for example, research on publicly disclosed information about market participants) run on a separate external model API. By technical control, draft materials and other unpublished Customer Content are never sent on this path; it processes public information only.

2.3 Processing location. Model inference on the draft path currently runs in AWS regions in the United States. Customer Content on this path is encrypted in transit, processed transiently, and not durably stored in those regions. Primary storage of Customer Content resides in Upside's production cloud environment. Customer acknowledges the United States processing described here and in the Privacy Policy.

2.4 Output labeling. AI-generated Output is identified as such in the portal and in exports, and carries the standing legend required by the Terms ("Draft for internal review. Not disclosure advice. Route to counsel and your Qualified Person before release." or equivalent).


3. Security Program

Upside maintains a written information security program aligned with SOC 2 Trust Services Criteria, documented in the Upside Information Security Policy Manual and reviewed at least annually. Its core controls as applied to the Service:

3.1 Encryption. All data in transit is encrypted using TLS 1.2 or higher. All data at rest, including databases, file storage, and backups, is encrypted using AES-256 or equivalent. Credentials and keys are held in a dedicated secrets management system; encryption keys are managed through cloud provider key management services and rotated on schedule.

3.2 Access control. Access follows least privilege and need-to-know. Multi-factor authentication is required for all access to production systems, cloud consoles, code repositories, and administrative tools. Production access to Customer Content is restricted to designated personnel with a documented business need; privileged sessions are logged. Access reviews run quarterly, and departing personnel are deprovisioned within 24 hours.

3.3 Tenant isolation. The platform enforces strict per-customer isolation at the database and application layers: tenant identifiers on all customer data, tenant-context authorization checks on every request, per-tenant processing in all AI pipelines with no cross-tenant aggregation, caching, or embedding leakage, and automated testing that tenant boundaries cannot be bypassed. Multiple public companies using the platform cannot access one another's drafts, jobs, or Output.

3.4 Confidentiality surfaces. Every screen displaying draft materials shows its confidentiality state. Share links, where offered, are access-logged and expiring. No third-party analytics or telemetry runs on draft-bearing screens.

3.5 Logging and monitoring. Authentication, authorization, data access, administrative, and AI-processing events are logged (metadata only, never raw draft text), retained for at least 12 months in an append-only system, and monitored with alerting for anomalous activity.

3.6 Secure development and operations. Changes reach production through peer-reviewed pull requests and automated CI/CD pipelines with dependency and security scanning. Production data is not used in development or test environments without anonymization. Infrastructure runs across multiple availability zones; encrypted backups are taken at least daily with tested restoration, targeting a recovery time objective of 4 hours and a recovery point objective of 1 hour.

3.7 Personnel. All personnel complete security awareness training at hire and annually, are bound by confidentiality obligations, and are subject to internal policies prohibiting trading in the securities of any customer while in possession of that customer's MNPI and prohibiting tipping or other misuse.

3.8 Vulnerability management. Automated dependency scanning runs on every build, infrastructure scanning at least monthly, and third-party penetration testing at least annually, with remediation on defined timelines by severity.


4. Subprocessors

4.1 Current subprocessors.

SubprocessorPurposeLocation of processing
Amazon Web Services, Inc.Cloud hosting, storage, and model inference (AWS Bedrock, zero-data-retention mode on the draft path)Canada/United States (hosting); United States (model inference)
[Payment processor, e.g. Stripe, Inc.]Subscription billing and card processingUnited States/Canada
[Email/support tooling]Transactional email and customer support[confirm]

External model API providers used on the public-information path (Section 2.2) do not receive Customer Content and are therefore not subprocessors of Customer Content; they are listed here for transparency: [x.ai / confirm current provider].

4.2 Requirements and changes. Each subprocessor that processes Customer Content is bound by a written agreement imposing data protection obligations consistent with this Data Policy, including prohibition of training on Customer Content, breach notification, and deletion on termination. Upside evaluates subprocessor security documentation (SOC 2 or equivalent) before onboarding and annually. Upside will update the subprocessor list and notify customers through the portal or by email at least 15 days before adding a subprocessor that will process draft materials; if Customer reasonably objects on data protection grounds and Upside cannot offer an alternative, Customer may cancel under the Terms.


5. Retention, Purge, and Deletion

5.1 Draft materials purge. Draft materials and associated Output for a given job are purged from production systems on the earliest of:

5.2 Corpus, baseline, and account data. Customer's corpus, baseline report, voice profile, and job history (excluding purged draft materials) are retained for the duration of the subscription to operate the Service's history and evidence features.

5.3 Offboarding. Following termination or expiry of the Terms, Customer has until the end of its access period to export its data. Upside deletes Customer Content and Output from production systems within 90 days of termination, except where retention is required by law. Billing and audit records are retained as required by law.

5.4 Backups. Deleted and purged content ages out of encrypted backups on the backup rotation schedule (daily backups retained 30 days; monthly backups retained 12 months) and is not restored to production except transiently, and subject to re-deletion, in the course of disaster recovery.

5.5 Media disposal. Storage media disposal follows NIST 800-88 guidelines.


6. Incident Response and Breach Notification

Upside maintains a documented incident response process with defined severity levels, escalation, containment, forensics preservation, and post-incident review. If Upside confirms unauthorized access to or disclosure of Customer Content, Upside will notify affected customers without undue delay and in any event within 72 hours of confirmation, describing the nature of the incident, the data involved, the actions taken, and recommended steps. Upside will cooperate reasonably with Customer's own assessment, including where the incident may bear on Customer's disclosure obligations. Notification is not an admission of fault or liability.


7. Customer Responsibilities (Shared Responsibility)

Security of Customer Content is shared. Customer is responsible for:

Upside is not responsible for incidents to the extent arising from compromise of Customer's credentials, devices, or systems, from Customer's sharing of exports, or from Customer's failure to meet the responsibilities above.


8. Risk Factors and Allocation of Responsibility

Customer acknowledges the following risks, which no provider can eliminate, and agrees that the Terms allocate them as stated there:

Responsibility allocation. UPSIDE'S RESPONSIBILITY AND LIABILITY IN CONNECTION WITH ANY SECURITY INCIDENT, DATA LOSS, DATA CORRUPTION, OR UNAUTHORIZED ACCESS TO OR DISCLOSURE OF CUSTOMER CONTENT, HOWEVER ARISING, ARE LIMITED AS SET OUT IN THE TERMS, INCLUDING THE EXCLUSION OF INDIRECT AND CONSEQUENTIAL DAMAGES AND THE AGGREGATE LIABILITY CAP IN SECTION 13 OF THE TERMS. UPSIDE'S COMMITMENTS REGARDING SECURITY ARE TO MAINTAIN THE PROGRAM AND CONTROLS DESCRIBED IN THIS DATA POLICY, NOT TO GUARANTEE THAT INCIDENTS WILL NEVER OCCUR. THIS ALLOCATION IS A BARGAINED-FOR TERM REFLECTED IN THE PRICE OF THE SERVICE.


9. Audits and Documentation

Upon reasonable written request, no more than once annually, Upside will make available to Customer its then-current security documentation (security policy summaries, penetration test attestations, and, when available, SOC 2 reports) under confidentiality. On-site or technical audits are not offered at the Service's standard pricing but may be agreed in an Order Form.

10. Changes

Upside may update this Data Policy as its practices and infrastructure evolve, provided updates do not materially reduce the protections for Customer Content during a paid subscription period. Material changes follow the notice mechanics in the Terms.

Contact: hello@upsidepr.ai (security reports: mark "Security" in the subject line).