InvestConclave
Security

A posture you can defend

Deal documents are among the most sensitive things a company shares. This page describes exactly how we handle them — no more, and no less.

01

How we protect your data

The controls below are live in the product today.

Roles and permissions

Each person’s role decides what they can see and do, and the server enforces it, not just the screen. Invite by email as Owner, Manager, Co-founder, Founder, Investor or Legal; resend or revoke an invitation, and invitations expire. Each organisation’s data is kept separate.

Audit trail

View links, downloads, invitations, role changes and deletions are logged. Filter the log and export it to CSV or PDF.

Encryption

Your documents are encrypted in transit and at rest.

Upload checks

Every upload is scanned for malware, and its real content is checked against its file type, so renamed or disguised files are rejected.

NDA and downloads

Members accept the room’s NDA before they see any document, and accept it again when it changes. Every downloaded PDF carries the viewer’s email and the date.

02

Where your documents live

The Pitch Forge application and document storage are hosted in Mumbai, India; some AI processing uses third-party AI providers. Your documents are not used to train AI models.

We deliberately do not publish the details of our infrastructure. If your legal or security team needs specifics for a review, write to security@investconclave.com and we will answer them directly, under NDA where appropriate.

03

Sub-processors

The categories of third party that may process customer data on our behalf.

CategoryPurpose
Cloud infrastructure and storageHosting, document storage, and upload scanning.
AI model providersGenerating grounded answers and extracting figures from your documents.
Transactional emailAccount, invitation, and notification email.
Edge network and DNSServing and protecting our public surfaces.
Form and productivity toolingHandling early-access requests.

The current list of named sub-processors is available on request at hello@investconclave.com, and is provided as part of our DPA. We give notice of material changes.

04

Reporting a vulnerability

If you believe you have found a security issue, tell us at security@investconclave.com. We read every report, we will acknowledge you, and we will not pursue anyone acting in good faith.

Our contact details are also published at /.well-known/security.txt.

On certifications

We do not claim any certification today. If your review needs evidence of a specific control, ask us and we will show you.

Ask the room. Get the page.

Early access comes with personal onboarding: a person from our team walks you through your room.