Security and compliance
IR platform security and data protection
Audit trail
Northwind Industrial, NWND- 09:41 L. Ortega, Legal Approved announcement draft, step 2 of 3 Approval
- 09:37 Copilot Flagged potential MNPI in an outgoing email, sending paused MNPI flag
- 09:12 M. Chen, IR Revoked data room access for one contact at a fund Access
- 08:58 M. Chen, IR Logged one-on-one call with a fund, Reg FD review Interaction
- 08:30 System SSO sign in from an allowed IP range Sign in
Sample data. Retention 7 years on Public and Enterprise.
01 Access
Roles and permissions decide who sees what
Every person in a workspace has a role. The role decides which modules they open, what they can change and what they can only read.
| Permission | Owner | Admin | IR | Legal | Viewer |
|---|---|---|---|---|---|
| Manage plan and billing | Yes | Yes | /No | /No | /No |
| Invite and remove users | Yes | Yes | /No | /No | /No |
| Edit investor CRM and meetings | Yes | Yes | Yes | /No | /No |
| Grant and revoke data room access | Yes | Yes | Yes | /No | /No |
| Approve announcements | Yes | Yes | /No | Yes | /No |
| Maintain insider lists | Yes | Yes | /No | Yes | /No |
| Read briefs and reports | Yes | Yes | Yes | Yes | Yes |
Approval chains
Announcements need the approvals you set before they can be published. Outreach sequences need an approver before the first email leaves. Enterprise adds custom roles and approval chains per issuing entity, for groups with subsidiaries and bond programmes.
Sign in and SSO
Accounts confirm their email with a code before they open a workspace. Enterprise connects SSO through SAML and provisions or removes users through SCIM, so a person who leaves your company loses access when your identity provider says so. Enterprise can also limit sign in to an IP allow list.
02 Audit trail
Every action recorded, kept for up to 7 years
The audit trail records who did what, when, from which IP address, and what the record looked like before and after. It covers sign ins, permission changes, approvals, data room access and every logged investor interaction.
12 months
Audit trail retention on Growth
7 years
Audit trail retention on Public
7 years
Retention on Enterprise, plus audit export and retention policies
03 Encryption
Encrypted in transit and at rest
In transit
The app, the hosted IR pages and data room links work over HTTPS only. Connections between the app and our providers are encrypted as well.
At rest
Databases, data room files and backups are encrypted at rest with the hosting provider. Files are stored in private object storage and served through short lived signed links, never through a public address.
04 Data rooms
Watermarks and access you can take back
Each data room has folder permissions per investor contact. Before a contact opens anything, they accept your NDA text with a click, and the acceptance is stored with date and IP.
Every page a contact views carries a dynamic watermark with their name, firm and the time of viewing. When a process ends or a fund drops out, revoke access in one step and links stop working at once. Rooms can also expire on a date you set.
View analytics show which contact opened which document and for how long, so you see interest without asking. Read more about the secure data room.
Series B data room, access
Watermark on| Contact | Level | NDA | Status |
|---|---|---|---|
| Harbor Creek Capital | Full | Accepted | Active |
| Alder Point Partners | Financials | Accepted | Active |
| Westlake Growth Fund | Teaser | Accepted | Revoked |
Sample data, fictional funds.
05 MNPI guardrails
Guardrails for Regulation FD and MAR
Selective disclosure is a legal risk for every listed issuer. The product helps your team catch it before a message leaves and keeps the record afterwards.
MNPI flags
Issuer Copilot reviews outgoing emails, talking points and drafts and flags text that may contain material non-public information, such as unannounced results or a pending transaction. A flagged message waits for a person to decide.
Interaction log
Every investor meeting, call and email is logged with participants, date and summary, ready for Reg FD and MAR review by your legal team.
Insider lists and approvals
On Public and Enterprise, the material event log, MAR insider lists and approval before publishing sit in the disclosure management software module.
Flags support your controls. They do not replace them, and the issuer stays responsible for what it discloses and to whom.
06 Enterprise controls
What Enterprise adds for security reviews
| Control | Growth | Public | Enterprise |
|---|---|---|---|
| Roles and permissions | Included | Included | Included |
| Encryption in transit and at rest | Included | Included | Included |
| Data room watermark and revocation | Included | Included | Included |
| Audit trail | 12 months | 7 years | 7 years plus export |
| SSO (SAML) and SCIM provisioning | /Not included | /Not included | Included |
| Custom roles and approval chains per entity | /Not included | /Not included | Included |
| IP allow list | /Not included | /Not included | Included |
| Data residency choice, EU or US | /Not included | /Not included | Included |
| DPA and security questionnaire pack | /Not included | /Not included | Included |
| 99.9 percent uptime SLA | /Not included | /Not included | Included |
The security questionnaire pack answers the questions procurement and IT teams usually send, and the DPA covers processing on your behalf. Both are part of the Enterprise plan. We describe our controls as they are and do not claim certifications we do not hold.
07 Resilience
Backups and incident notification
Backups
Databases and stored files are backed up every day, encrypted, and kept separately from the live system.
Incident notification
If a security incident affects your workspace data, the workspace owner hears from us by email without undue delay, with what happened, what data is involved and what we are doing. Questions about security go to [email protected].
Questions
Questions issuers ask before they start
How is investor data protected?
Do you support single sign-on?
Is our data used to train AI models?
How long are audit logs kept?
Related
Related tools in the same workspace
Check the controls on your own data
Start with a sample brief from public filings. Enterprise adds SSO, SCIM, IP allow list, data residency and the security questionnaire pack.