Privacy Policy
v2026.08.28
- Document version
- v3.13
- Effective
- 2026-08-28
- Change
- material — supersedes v2026.08.27
- SHA-256
- e0d0bb2e24862530c2308f2babcd447aabd02ec6c9110c571c50f2e77bf05566
Note
Octav removed from the third-party list. The firm no longer uses it, and naming a provider that does not receive client information is a statement that goes stale the moment anything changes. The engagement was VERIFIED before removal rather than assumed: pw-api carries no Octav API client and no env binding - the only non-comment references are two audit-action names, with DeBank as a positive control showing real modules - and production audit_log holds zero onchain.octav rows against 33,704 onchain rows overall, so no data of any kind ever reached it. Classified material because it changes the named set of recipients of client information, though under the companion List of Subprocessors' own test it expands no category of data shared, no geography and no class of AI service; removal narrows the set rather than widening it. Two unused credentials remain in Secret Manager pending an operator deletion, and the migrations naming Octav are dated records left unedited.
To verify this is the document we published, compare the SHA-256 of your copy to the value above — for example sha256sum on Linux or macOS, or Get-FileHash in PowerShell.