A posture you can defend
Deal documents are among the most sensitive things a company shares. This page describes exactly how we handle them — no more, and no less.
How we protect your data
Every control below is live in the product today.
Access control
Permissions run from the workspace down to the individual file. Roles are least-privilege by default, and access can be granted or revoked per document at any point in a deal.
Audit trail
Every action is recorded — who opened what, when, and what changed. The log is complete, exportable, and captures denied attempts as well as successful ones.
Encryption
Your documents are encrypted in transit and at rest, at every point between your browser and storage.
Upload scanning
Every file is scanned for malware before it becomes available to anyone in the room. Nothing is served to a counterparty until it clears.
Document handling
Links to documents expire. Viewing can be watermarked. Each room can restrict which file types are accepted and how much can be stored.
Account security
Two-factor authentication is available to every user, and a room can require it of its guests. Rooms can gate entry behind an NDA and sign idle sessions out automatically.
Where your data lives
Customer data is hosted in India.
We deliberately do not publish the details of our infrastructure. If your legal or security team needs specifics for a review, write to security@investconclave.com and we will answer them directly, under NDA where appropriate.
Sub-processors
The categories of third party that may process customer data on our behalf.
| Category | Purpose |
|---|---|
| Cloud infrastructure and storage | Hosting, document storage, and upload scanning. |
| AI model providers | Generating grounded answers and extracting figures from your documents. |
| Transactional email | Account, invitation, and notification email. |
| Edge network and DNS | Serving and protecting our public surfaces. |
| Form and productivity tooling | Handling early-access requests. |
The current list of named sub-processors is available on request at hello@investconclave.com, and is provided as part of our DPA. We give notice of material changes.
Reporting a vulnerability
If you believe you have found a security issue, tell us at security@investconclave.com. We read every report, we will acknowledge you, and we will not pursue anyone acting in good faith.
Our contact details are also published at /.well-known/security.txt.
On certifications
We do not hold third-party security certifications. Everything on this page describes controls that are live in the product today — we would rather tell you exactly what we do than point at a badge. If your review needs evidence of a specific control, ask us and we will show you.
Run your next round on InvestConclave.
We’re onboarding our first customers personally — so the AI agents can start handling the questions you’d rather not answer for the hundredth time.