Our Company
An asset manager built on research, transparency, and a long horizon — managing capital for individuals and institutions.

We place paramount importance on security, recognizing it as the cornerstone of trust in the realm of our investment.
We work hard to protect your information. Vest Node Capitals information security and data protection is driven by the same commitment to excellence that we apply to understanding the financial needs of our clients.
At Vest Node Capitals, we employ a multi-layered approach to security. No single control is asked to carry the whole burden; each one is intended to catch what another might miss. Among the systems we use to protect information are the controls described below.
The controls we operate
Firewalls
Firewalls sit between our networks and the outside world, deciding which traffic may reach our systems and which is refused. They are the first filter rather than the only one, and their rules are reviewed as systems change, so that access granted for one purpose does not quietly remain open for another.
Malware identification
Malware identification looks for hostile software that has already arrived on a system, rather than for something trying to get in. It combines signature-based detection, which recognises known threats, with behavioural monitoring, which flags activity that does not match how a system normally behaves.
Fraud detection
Fraud detection looks for patterns that suggest an account or a transaction is not what it claims to be. Unusual timing, unfamiliar locations, and behaviour that breaks from a client's normal pattern are surfaced for review rather than processed silently, so that a person can assess what the system has flagged.
Data-loss prevention
Data-loss prevention is about keeping sensitive information inside the boundary it belongs to. It inspects how data moves — through email, uploads, and connected devices — and blocks or flags transfers that would place client information where it should not be, whether the cause is a mistake or intent.
Email filtering
Email filtering scans incoming and outgoing mail for malicious links, attachments, and spoofed senders before a message reaches a person's inbox. Because email remains one of the most common routes for both fraud and malware, treating it as an untrusted channel is a deliberate choice rather than a default.
Virus controls
Virus controls monitor endpoints and servers for known malicious code and quarantine it when it is found. They are maintained as a standing control rather than a one-time installation, because the code they defend against changes continuously and a control that is not kept current quickly stops being useful.
System redundancy
System redundancy means that critical functions do not depend on a single machine, link, or location. If one component fails, another can take over, which reduces the chance that a local fault becomes a full outage. Redundancy is a design principle for availability; it is not a promise that no interruption will ever occur.
Network segmentation
Network segmentation divides our environment into separate zones, so that a problem in one part cannot spread freely to the rest. Systems are grouped by the function they perform and the data they touch, and the connections between zones are kept to what is genuinely required.
Independent assurance
Controls are reviewed on a regular cycle and independent reviews are scheduled periodically. Findings feed back into how systems and access are configured.
How we operate day to day
Controls are only as good as the practices around them, so we organise access around least privilege: a person is given the access their role requires and no more, and that access is reviewed rather than assumed. Reviews look for accounts that should have been closed, permissions that have accumulated beyond their original purpose, and exceptions that were granted temporarily and never withdrawn. The point is not process for its own sake. Most avoidable incidents begin with access that was broader or older than it needed to be.
We also plan for the possibility that a control will fail, because any honest account of security has to. We maintain an incident response process that sets out who is responsible for what, how a problem is contained, and how it is communicated to the people affected. Incidents are reviewed afterwards to find the cause rather than a convenient explanation, and what is learned is fed back into how systems and access are configured. A firm that cannot describe what it would do when something goes wrong is relying on luck.
None of this removes risk, and we would not claim that it does. Security is the practice of reducing the likelihood and the impact of failure, not of promising that failure cannot occur. We would rather describe the controls we actually operate, and be candid about the ones whose effectiveness depends on constant maintenance, than offer an assurance we cannot stand behind.