Hermitage

Security

Hermitage Technologies, LLC

Last Updated: October 3, 2026

Hermitage holds sensitive information, and it is built with that in mind from the ground up. Security is an active, ongoing program, reviewed by an independent security consulting firm, and this page is updated as that work progresses.

In place today

  • Every firm’s data is separated from every other firm’s, and each user sees only what their role allows.
  • Clients see their own information only, and anyone else sees a client’s vault only after the client signs an authorization naming them, what they may see and when.
  • Users sign in with a single-use email link or their Google or Microsoft account, so Hermitage stores no passwords.
  • All data travels over encrypted connections.
  • An audit log records changes to client data, every document viewed or downloaded, and every access by people a client has authorized.
  • Payments are handled by Stripe; Hermitage never sees or stores card numbers.
  • The support chat never receives client data, and Hermitage’s AI providers do not train on any data Hermitage sends them.

Underway

  • A program to meet SOC 2 standards, with a formal audit to follow.

Security questions, and requests for Hermitage’s data processing addendum or a completed security questionnaire, can be sent to security@hermitage.estate.