Security and trust

Security at TakePublic

Draft filings can contain inside information the market has not seen, so security is designed into the filing workflow, not added around it.

Hosting
Cloudflare edge, filing documents in two regions
Encryption
In transit and in storage
Access
By role, with a second sign-in step
Audit trail
Recorded in order, cannot be rewritten
Subprocessors
11 services, full list
TRUST
TP-SEC Security controls Designed for filing workflows

Encryption and secrets

Your EDGAR codes and accounting connections are encrypted before they are stored, and every connection to TakePublic is encrypted.

The audit trail

Every action is recorded in order. Nothing in the record can be changed or removed, and we check it every day.

The counsel gate

No filing prepared in TakePublic reaches EDGAR until your securities attorney has signed off on the exact document that will be sent.

  1. 01Version fixed
  2. 02Counsel signs it
  3. 03Checked again at send
  4. 04Sent as signed

Access and authentication

Each person sees only the work their seat is for, and draft filings are handled as inside information.

Record retention

Signed records, attestations and the audit log are kept for as long as TakePublic provides the Service and at least seven years, longer than the five years Rule 302(b) of Regulation S-T sets for signed filing records.

AI and your data

Your books and filings are never used to train AI models. Anthropic provides the drafting model.

Integrations and vendors

8 outside services run the product, each for one stated purpose.

Every service that handles customer data, including error monitoring and analytics, is listed with its purpose on the subprocessors page.

Compliance status

SOC 2 in preparation; not yet certified. Documents on request under NDA.

SOC 2
in preparation, not yet certified
$2M
Technology E&O insurance, aggregate
$2M
Cyber insurance, aggregate
8
controls in the product today

Control status is monitored continuously and published on the TakePublic Trust Center, where documents can be requested under NDA. Both policies are with an A-rated carrier, effective September 1, 2026; certificates of insurance are available to customers on request.

Implemented in the product today

Security articles in the help center

The step-by-step detail behind this page: data protection, the audit trail, and the second sign-in step.

Frequently asked questions

How are EDGAR filer codes protected?

Your EDGAR codes, including the CCC, are encrypted before they are saved and are never stored in readable form. The key that unlocks them is held separately, and if it is ever unavailable the system stops rather than carry on without protection.

Can a filing be submitted without a sign-off?

Not a filing prepared in TakePublic: it reaches EDGAR only after a sign-off on the exact version being sent, by the reviewer your company designates for a Form 3, 4 or 5 or by your securities attorney for any other filing, and any later edit holds the filing until they sign again. A Form 3, 4 or 5 uploaded as already reviewed and signed files exactly as uploaded, after the company attaches the signed page and attests to its review.

Does TakePublic train AI models on customer content?

No. Your books and filings are never used to train AI models, and draft filings are treated as inside information that only the people whose role needs them can see.

What is TakePublic's SOC 2 status?

TakePublic is preparing for SOC 2, with control status monitored continuously on the TakePublic Trust Center. Certification has not been completed, and this page does not represent otherwise.

TakePublic is a technology platform, not a law firm, broker-dealer, or auditor. Forms 3, 4 and 5 prepared in TakePublic file only after the reviewer the company designates, such as its securities counsel, signs off; any other filing prepared in TakePublic files only after a licensed securities attorney signs off.