Skip to content
Issuers

Security and compliance

IR platform security and data protection

Issuers protects investor data with role based access, encryption in transit and at rest, watermarked data rooms and a full audit trail of every action and investor interaction, kept for up to 7 years.

01 Access

Roles and permissions decide who sees what

Every person in a workspace has a role. The role decides which modules they open, what they can change and what they can only read.

Approval chains

Announcements need the approvals you set before they can be published. Outreach sequences need an approver before the first email leaves. Enterprise adds custom roles and approval chains per issuing entity, for groups with subsidiaries and bond programmes.

Sign in and SSO

Accounts confirm their email with a code before they open a workspace. Enterprise connects SSO through SAML and provisions or removes users through SCIM, so a person who leaves your company loses access when your identity provider says so. Enterprise can also limit sign in to an IP allow list.

02 Audit trail

Every action recorded, kept for up to 7 years

The audit trail records who did what, when, from which IP address, and what the record looked like before and after. It covers sign ins, permission changes, approvals, data room access and every logged investor interaction.

12 months

Audit trail retention on Growth

7 years

Audit trail retention on Public

7 years

Retention on Enterprise, plus audit export and retention policies

03 Encryption

Encrypted in transit and at rest

In transit

The app, the hosted IR pages and data room links work over HTTPS only. Connections between the app and our providers are encrypted as well.

At rest

Databases, data room files and backups are encrypted at rest with the hosting provider. Files are stored in private object storage and served through short lived signed links, never through a public address.

04 Data rooms

Watermarks and access you can take back

Each data room has folder permissions per investor contact. Before a contact opens anything, they accept your NDA text with a click, and the acceptance is stored with date and IP.

Every page a contact views carries a dynamic watermark with their name, firm and the time of viewing. When a process ends or a fund drops out, revoke access in one step and links stop working at once. Rooms can also expire on a date you set.

View analytics show which contact opened which document and for how long, so you see interest without asking. Read more about the secure data room.

05 MNPI guardrails

Guardrails for Regulation FD and MAR

Selective disclosure is a legal risk for every listed issuer. The product helps your team catch it before a message leaves and keeps the record afterwards.

MNPI flags

Issuer Copilot reviews outgoing emails, talking points and drafts and flags text that may contain material non-public information, such as unannounced results or a pending transaction. A flagged message waits for a person to decide.

Interaction log

Every investor meeting, call and email is logged with participants, date and summary, ready for Reg FD and MAR review by your legal team.

Insider lists and approvals

On Public and Enterprise, the material event log, MAR insider lists and approval before publishing sit in the disclosure management software module.

Flags support your controls. They do not replace them, and the issuer stays responsible for what it discloses and to whom.

06 Enterprise controls

What Enterprise adds for security reviews

Security controls per plan
ControlGrowthPublicEnterprise
Roles and permissions Included Included Included
Encryption in transit and at rest Included Included Included
Data room watermark and revocation Included Included Included
Audit trail 12 months 7 years 7 years plus export
SSO (SAML) and SCIM provisioning /Not included /Not included Included
Custom roles and approval chains per entity /Not included /Not included Included
IP allow list /Not included /Not included Included
Data residency choice, EU or US /Not included /Not included Included
DPA and security questionnaire pack /Not included /Not included Included
99.9 percent uptime SLA /Not included /Not included Included

The security questionnaire pack answers the questions procurement and IT teams usually send, and the DPA covers processing on your behalf. Both are part of the Enterprise plan. We describe our controls as they are and do not claim certifications we do not hold.

07 Resilience

Backups and incident notification

Backups

Databases and stored files are backed up every day, encrypted, and kept separately from the live system.

Incident notification

If a security incident affects your workspace data, the workspace owner hears from us by email without undue delay, with what happened, what data is involved and what we are doing. Questions about security go to [email protected].

Questions

Questions issuers ask before they start

How is investor data protected?
Data is encrypted in transit with TLS and at rest on the hosting provider. Access inside a workspace follows roles, data room documents carry a dynamic watermark with the viewer name, and every access, change and investor interaction lands in the audit trail.
Do you support single sign-on?
Yes, on the Enterprise plan. Enterprise workspaces connect their identity provider through SAML for sign in and SCIM for user provisioning and removal. Growth and Public use email and password with a code sent by email at signup.
Is our data used to train AI models?
No. Workspace content is sent to the AI model provider only to answer the request you make. We do not use your documents, CRM or drafts to train any model.
How long are audit logs kept?
Growth keeps the audit trail for 12 months. Public and Enterprise keep it for 7 years. Enterprise adds audit export and retention policies, so you can hold the record in your own archive as well.

Check the controls on your own data

Start with a sample brief from public filings. Enterprise adds SSO, SCIM, IP allow list, data residency and the security questionnaire pack.

Compare plans