A posture you can defend
Deal documents are among the most sensitive things a company shares. This page describes exactly how we handle them — no more, and no less.
How we protect your data
The controls below are live in the product today.
Roles and permissions
Each person’s role decides what they can see and do, and the server enforces it, not just the screen. Invite by email as Owner, Manager, Co-founder, Founder, Investor or Legal; resend or revoke an invitation, and invitations expire. Each organisation’s data is kept separate.
Audit trail
View links, downloads, invitations, role changes and deletions are logged. Filter the log and export it to CSV or PDF.
Encryption
Your documents are encrypted in transit and at rest.
Upload checks
Every upload is scanned for malware, and its real content is checked against its file type, so renamed or disguised files are rejected.
NDA and downloads
Members accept the room’s NDA before they see any document, and accept it again when it changes. Every downloaded PDF carries the viewer’s email and the date.
Where your documents live
The Pitch Forge application and document storage are hosted in Mumbai, India; some AI processing uses third-party AI providers. Your documents are not used to train AI models.
We deliberately do not publish the details of our infrastructure. If your legal or security team needs specifics for a review, write to security@investconclave.com and we will answer them directly, under NDA where appropriate.
Sub-processors
The categories of third party that may process customer data on our behalf.
| Category | Purpose |
|---|---|
| Cloud infrastructure and storage | Hosting, document storage, and upload scanning. |
| AI model providers | Generating grounded answers and extracting figures from your documents. |
| Transactional email | Account, invitation, and notification email. |
| Edge network and DNS | Serving and protecting our public surfaces. |
| Form and productivity tooling | Handling early-access requests. |
The current list of named sub-processors is available on request at hello@investconclave.com, and is provided as part of our DPA. We give notice of material changes.
Reporting a vulnerability
If you believe you have found a security issue, tell us at security@investconclave.com. We read every report, we will acknowledge you, and we will not pursue anyone acting in good faith.
Our contact details are also published at /.well-known/security.txt.
On certifications
We do not claim any certification today. If your review needs evidence of a specific control, ask us and we will show you.
Ask the room. Get the page.
Early access comes with personal onboarding: a person from our team walks you through your room.