Security

Built for SOC 2 from day one.

Tenant isolation

Row-level security on every tenant-scoped table. Every read and write is gated by verified Studio membership — enforced in the database, not the browser.

Least-privilege roles

Platform roles are separate from Studio roles. Sensitive records (valuations, equity, LP data) require explicit role or grant.

Append-only audit

Every sensitive action writes a hash-chained audit event. Chain integrity is verified on a schedule and reported to auditors.

Scoped external access

LPs see only published, permissioned reports. Experts see only the exact fields you scoped — snapshotted at request time, expiring by default.

Encrypted end to end

TLS in transit, encryption at rest, per-field encryption for sensitive PII, short-lived signed URLs for all tenant files.

One-shot bootstrap

The first platform admin is created through a secure, single-use bootstrap flow that permanently disables itself.