You carry client books, investor identities, and money in motion. Here is exactly how all of it is protected, written in plain words your IT reviewer can check.
Every row in every table belongs to your workspace, and the database itself enforces the wall, not just the application code. No other customer can ever see your records.
Everything travels encrypted. Connection tokens, investor identity details, and sign-in secrets are encrypted again at the application layer on top of encrypted storage. Revealing investor identity details requires typing your password again.
Authenticator apps, text codes, and email codes, with single-use backup codes for recovery and an admin reset as the fallback. The investor portal requires two-step sign-in, no exceptions.
A 12-character password policy enforced on our servers, and every new password is checked against the public breach registry in a way that never sends the password itself anywhere.
Our Microsoft connection is from a verified publisher (TenthAvenue Labs Inc.). Google access is limited to your calendar. Every member connects and disconnects their own accounts, and access can be revoked any time.
Invitations, role changes, sign-in resets, domain changes, and identity lookups all land in an audit log. Sign-ins through Google or Microsoft follow the rules your company already set there, including offboarding.
Send it over. We answer them directly, with the engineers who built the controls in the loop.
Contact us