Skip to main content
Security and privacy

Protecting your program’s data is part of the product.

Applicants trust you with their plans, financials and documents. Here is how we protect them, and how we work within your security and procurement requirements.

Identity

Authentication and access

  • Sign-in is passwordless, through a specialised identity provider: one-time email codes, or Google or LinkedIn single sign-on. The platform never stores passwords.
  • The platform is private by default. Every invitation and access link goes through an authenticated gateway, so nothing is reachable without a valid session.
  • Access is governed by role-based permissions for applicants, advisors, investors and administrators, enforced in the application’s authorization layer.
  • Sessions use secure, HTTP-only cookies over HTTPS and expire after 7 days. Public endpoints are rate-limited against abuse.
Isolation

Your program’s data stays in your program

  • Data is scoped to organisations, not loosely to individuals. Matching, browsing and visibility are filtered by organisation throughout the application.
  • A visibility boundary controls who can see whom, so an applicant in a private cohort is not visible to anyone outside it.
  • Data room access is explicit and granted per organisation. The applicant decides who sees which folders or files, access is requested and approved through a controlled workflow, and data room activity is recorded in an audit log.
Protection

Data protection

  • All traffic is encrypted in transit with TLS.
  • The application runs on a managed cloud platform, with documents and media in managed object storage.
  • Database backups run automatically every day and are kept on a rolling 30-day basis, with alerts on success and failure.
  • Deleted files are never removed immediately: they can be restored for 30 days, and production files are mirrored nightly to a separate backup.
AI

AI with a record

  • AI reads applications, profiles and documents through vetted model providers to produce summaries, extractions and assessments.
  • Every AI call is logged with the organisation that triggered it, and each galaxy has a monthly AI spend ceiling.
  • AI gives a first read with its reasoning. Your reviewers make the decisions, and every assessment is stored with its evidence and rubric version.
Hardening

Application security

  • Standard protections against common web vulnerabilities, including cross-site request forgery, SQL injection and cross-site scripting.
  • A content security policy and security headers are set on every response, and uploaded files are served so they cannot be run as scripts.
Observability

Logging and monitoring

  • The platform records application errors, outbound email, scheduled jobs, administrative sessions, AI calls and data room access, for operations and audit.
Privacy

Privacy

  • We collect the personal and business information needed to run a program, such as name, email, location, and the profile content participants choose to provide.
  • Participants control what they share and with whom. We do not sell personal information.

We’ll meet your requirements

We’re happy to sign a mutual NDA and to discuss a data processing agreement that fits your requirements.

Send us your security questionnaire or framework and we’ll complete it directly, with any further detail your security team needs.

A fuller security overview, including our current list of sub-processors and what each one receives, is available on request.