Security

Built for the standards of institutional capital

Capital information is sensitive by definition. These are the principles the platform is being built to, stated plainly and without revealing implementation detail.

Encryption throughout

The platform is designed for encryption of data in transit and at rest, with modern protocols and managed keys.

Least privilege access

Access is designed around roles and need. Nobody, inside or outside the company, sees more than their role requires.

Audit and accountability

Meaningful actions are designed to be logged and attributable, so sensitive workflows such as data rooms carry a full history.

Data governance

Clear provenance for every data point, defined retention, and processes for correction and deletion. UK GDPR obligations are treated as a floor, not a ceiling.

Segregation of parties

Opportunity owners and investors each control what the other side sees. Disclosure is a deliberate act, never a default.

Tested before trusted

Security review and testing are planned as a standing discipline through development, not a launch week checkbox.

Honesty first

Certifications will be earned, not implied

We will publish security certifications and assessments when they are achieved. Until then, this page states design principles and commitments only. If you have specific security requirements for early access participation, ask us directly.

Ask us the hard questions

Security due diligence is welcome at any stage of the conversation.

Contact us