Trust Center

Draft — not for publication. Every claim on this page is pending review. See the checklist at the top of lib/trust/content.js.

Start your security review

View & download sensitive information · Ask for information

Overview

Private equity runs on confidential information. Deal documents, fund data, and portfolio company records are among the most sensitive assets a firm handles, and protecting them is the foundation Fundrev is built on. Use this Trust Center to review our security posture and request access to our security documentation.

Last updated 2026-08-29

Compliance

  • SOC 2Audited
  • GDPRAligned
  • CCPAAligned
  • VPATSelf-assessed

“Audited” means an independent firm issued an opinion. “Aligned” means we operate to the framework without certification. “Self-assessed” means we completed the document ourselves — we do not blur the three.

Documents

Product Security

  • Audit Logging
  • Data Security
  • Integrations

Data Security

  • Encryption-at-rest
  • Encryption-in-transit
  • Data Erasure

App Security

  • Responsible Disclosure
  • Application Penetration Testing
  • Secure Development Practices

AI

  • No Training on Your Data

    We do not use customer data to train, fine-tune, or improve any model — our own or a third party's.

  • In-Account Inference

    Model inference runs inside our own AWS account via Amazon Bedrock. Prompts and documents are not retained by the model provider.

  • Scoped Retrieval

    AI features answer only from material the asking user is already authorised to see; the same permission model governs both.

Access Control

  • Multi-Factor Authentication
  • Single Sign-On
  • SCIM Provisioning

Infrastructure

  • Hosting
  • Network Isolation
  • BC/DR

Endpoint Security

  • Disk Encryption

    Company devices enforce full-disk encryption.

  • Endpoint Protection

    Managed endpoint protection and anti-malware run on company devices.

  • Device Management

    Devices are inventoried and centrally managed, with screen lock enforced.

Corporate Security

  • Incident Response

    A documented process covering detection, containment, customer notification, and post-incident review.

  • Asset Management

    Assets are inventoried through their lifecycle, including secure disposal.

  • Background Checks & Training

    Staff complete background checks on hire and security awareness training thereafter.

Legal

  • Subprocessors

    The full list is published below. We notify customers of changes under the terms of the DPA.

  • Data Processing Agreement

    Our standard DPA is available on request.

  • Privacy Policy

    Published at fundrev.ai/privacypolicy.

Policies

29 in force

The policies we maintain and work to. The documents themselves are released as the Policy Book, on request.

  • Access Control Policy
  • Access Management Process
  • Anti-Malware Policy
  • Asset Data Disposal Policy
  • Asset Management Policy
  • Bring Your Own Device (BYOD) Policy
  • Change Management Policy
  • Code of Conduct Policy
  • Communication Policy
  • Customer Onboarding and Offboarding Policy
  • Cyber Risk Assessment Policy
  • Data Backup and Retention Policy

Subprocessors

The third parties we engage to process customer data on our behalf. Systems you connect yourself — your CRM, document store, or warehouse — remain yours and are not listed here.

CompanyPurposeLocationAdditional details
Amazon Web Services (AWS)Cloud ServicesUnited StatesHosting, compute, storage, and networking for the entire platform.Privacy portal: aws.amazon.com/privacy
Anthropic (via Amazon Bedrock)LLM InferenceUnited StatesModel inference for AI features, served inside our own AWS account. Not used to train models.Privacy portal: www.anthropic.com/legal/privacy
Amazon TextractDocument ExtractionUnited StatesText extraction from scanned and image-based documents.Privacy portal: aws.amazon.com/privacy
ZeptoMail (Zoho)Transactional Emailreview: confirm sending regionInvitations, notifications, and account mail. Recipient name, address, and message body.Privacy portal: www.zoho.com/privacy.html
MicrosoftIdentity FederationCustomer's own tenantSign-in for customers who use Microsoft Entra ID.Privacy portal: www.microsoft.com/en-us/privacy/privacystatement
GoogleIdentity FederationUnited StatesSign-in for users who choose Google as their identity provider.Privacy portal: policies.google.com/privacy

We notify customers of a change to this list under the terms of the Data Processing Agreement.

Questions, or a security concern

Security questionnaires, diligence requests, and vulnerability reports all reach the same team.

Documents & questionnaires

security@fundrev.ai

Report a vulnerability

security@fundrev.ai