InvestConclave
Security

A posture you can defend

Deal documents are among the most sensitive things a company shares. This page describes exactly how we handle them — no more, and no less.

01

How we protect your data

Every control below is live in the product today.

Access control

Permissions run from the workspace down to the individual file. Roles are least-privilege by default, and access can be granted or revoked per document at any point in a deal.

Audit trail

Every action is recorded — who opened what, when, and what changed. The log is complete, exportable, and captures denied attempts as well as successful ones.

Encryption

Your documents are encrypted in transit and at rest, at every point between your browser and storage.

Upload scanning

Every file is scanned for malware before it becomes available to anyone in the room. Nothing is served to a counterparty until it clears.

Document handling

Links to documents expire. Viewing can be watermarked. Each room can restrict which file types are accepted and how much can be stored.

Account security

Two-factor authentication is available to every user, and a room can require it of its guests. Rooms can gate entry behind an NDA and sign idle sessions out automatically.

02

Where your data lives

Customer data is hosted in India.

We deliberately do not publish the details of our infrastructure. If your legal or security team needs specifics for a review, write to security@investconclave.com and we will answer them directly, under NDA where appropriate.

03

Sub-processors

The categories of third party that may process customer data on our behalf.

CategoryPurpose
Cloud infrastructure and storageHosting, document storage, and upload scanning.
AI model providersGenerating grounded answers and extracting figures from your documents.
Transactional emailAccount, invitation, and notification email.
Edge network and DNSServing and protecting our public surfaces.
Form and productivity toolingHandling early-access requests.

The current list of named sub-processors is available on request at hello@investconclave.com, and is provided as part of our DPA. We give notice of material changes.

04

Reporting a vulnerability

If you believe you have found a security issue, tell us at security@investconclave.com. We read every report, we will acknowledge you, and we will not pursue anyone acting in good faith.

Our contact details are also published at /.well-known/security.txt.

On certifications

We do not hold third-party security certifications. Everything on this page describes controls that are live in the product today — we would rather tell you exactly what we do than point at a badge. If your review needs evidence of a specific control, ask us and we will show you.

Run your next round on InvestConclave.

We’re onboarding our first customers personally — so the AI agents can start handling the questions you’d rather not answer for the hundredth time.