← Back to home

Security

Your dealflow data is sensitive. Fondaco is designed from the ground up with fund-grade security: complete data isolation, encryption, and role-based access.

Multi-fund data isolation

Separate databases prevent one fund's team from accessing another's pipeline, LP records, or settings. Complete data separation is enforced at the infrastructure level.

Encryption everywhere

TLS 1.2+ for data in transit. AES-256 at rest. Documents stored in encrypted object storage with per-fund access controls.

Role-based access control

GP and Ops roles with granular permissions per fund. Expiring session tokens limit unauthorized access. Revoke access instantly when team members change.

Secure authentication

OAuth-based authentication with JWT session management. No stored passwords. Tokens rotate regularly and revoke instantly on logout.

Full data portability

Export all your data anytime — companies, notes, documents, investments, LP records — in CSV or JSON format. No lock-in, no data hostage.

No third-party data sharing

We never sell or monetize your data. AI processing happens on-demand only through enterprise providers that do not use your data for model training.

Infrastructure

Hosting

Cloud-hosted with automated backups and redundancy.

Database

PostgreSQL with automated daily backups and point-in-time recovery.

File Storage

S3-compatible encrypted object storage with per-fund access controls.

AI Providers

Enterprise-grade AI providers under data processing agreements. No model training on your data.

Have security questions? Contact us at hello@fondaco.ai