Product Security
- Audit Logging
- Data Security
- Integrations
Draft — not for publication. Every claim on this page is pending review. See the checklist at the top of lib/trust/content.js.
View & download sensitive information · Ask for information
Private equity runs on confidential information. Deal documents, fund data, and portfolio company records are among the most sensitive assets a firm handles, and protecting them is the foundation Fundrev is built on. Use this Trust Center to review our security posture and request access to our security documentation.
Last updated 2026-08-29
SOC 2Audited“Audited” means an independent firm issued an opinion. “Aligned” means we operate to the framework without certification. “Self-assessed” means we completed the document ourselves — we do not blur the three.
We do not use customer data to train, fine-tune, or improve any model — our own or a third party's.
Model inference runs inside our own AWS account via Amazon Bedrock. Prompts and documents are not retained by the model provider.
AI features answer only from material the asking user is already authorised to see; the same permission model governs both.
Company devices enforce full-disk encryption.
Managed endpoint protection and anti-malware run on company devices.
Devices are inventoried and centrally managed, with screen lock enforced.
A documented process covering detection, containment, customer notification, and post-incident review.
Assets are inventoried through their lifecycle, including secure disposal.
Staff complete background checks on hire and security awareness training thereafter.
The full list is published below. We notify customers of changes under the terms of the DPA.
Our standard DPA is available on request.
Published at fundrev.ai/privacypolicy.
The policies we maintain and work to. The documents themselves are released as the Policy Book, on request.
The third parties we engage to process customer data on our behalf. Systems you connect yourself — your CRM, document store, or warehouse — remain yours and are not listed here.
| Company | Purpose | Location | Additional details |
|---|---|---|---|
| Cloud Services | United States | Hosting, compute, storage, and networking for the entire platform.Privacy portal: aws.amazon.com/privacy | |
| LLM Inference | United States | Model inference for AI features, served inside our own AWS account. Not used to train models.Privacy portal: www.anthropic.com/legal/privacy | |
| Document Extraction | United States | Text extraction from scanned and image-based documents.Privacy portal: aws.amazon.com/privacy | |
| Transactional Email | review: confirm sending region | Invitations, notifications, and account mail. Recipient name, address, and message body.Privacy portal: www.zoho.com/privacy.html | |
| Identity Federation | Customer's own tenant | Sign-in for customers who use Microsoft Entra ID.Privacy portal: www.microsoft.com/en-us/privacy/privacystatement | |
| Identity Federation | United States | Sign-in for users who choose Google as their identity provider.Privacy portal: policies.google.com/privacy |
We notify customers of a change to this list under the terms of the Data Processing Agreement.
Security questionnaires, diligence requests, and vulnerability reports all reach the same team.
Documents & questionnaires
security@fundrev.aiReport a vulnerability
security@fundrev.ai