Capital Refinery
Security & Trust · Data Handling

Concrete data handling — designed for institutional procurement.

Private markets handle CIMs, credit agreements, rent rolls, operator data, LP letters. Capital Refinery is built for those documents from the ingest path through the IC anchor and the signed export — with the controls institutional procurement actually asks about.

What gets ingested, and how

  • PDFs (CIMs, credit agreements, lease abstracts, ESAs, PCAs, financial statements) — extracted with deterministic-first pipelines, LLM only as adjudication when deterministic misses
  • Spreadsheets (Excel models, financial packs, rent rolls, accounting exports) — cell-level lineage preserved
  • Operational data feeds for portfolio monitoring
  • Encrypted and locked PDFs supported with controlled extraction paths

Every figure carries a candidate trail back to the source cell, page, or table — not an LLM-generated reference, an extraction lineage.

Tenant isolation

Tenant boundaries are enforced in the database with row-level security, and every request carries a verified tenant. We are hardening this further ahead of SOC 2, and our security questionnaire describes the current controls.

  • Per-tenant database scoping enforced at middleware
  • Per-tenant document storage scoping enforced at object-storage
  • Per-tenant worker pre-warming for performance isolation
  • Per-tenant audit logs

Provenance — every figure, every export

  • Every KPI and Risk Signal carries an evidence chain back to the source document
  • Filename click-through on the Decision Timeline — see exactly which artifact produced a number
  • Every docx and xlsx export carries an evidence fingerprint of the dossier state at the moment of export
  • Optional signed share token — the LP can verify the report against the platform without contacting the GP
  • IC anchor immutability — the decision basis at approval cannot be backdated or rewritten

Audit trails

  • Override audit trail — every analyst override of a figure or assumption is recorded with principal, basis, timestamp
  • Share-token audit log — every LP-share token issuance recorded with principal, IP, user-agent and token hash
  • Decision-commit audit — every IC approval/conditional-support/reject writes an anchor event with full context
  • Action ownership trail — every assigned action with owner, deadline, resolution
Procurement-grade controls

What Capital Refinery does, concretely.

CapabilityControl areaCapital Refinery
Document ingestionDesigned for sensitive private-markets documents — encrypted PDFs, locked spreadsheets, confidential CIMsSource-document lineage on every figure
Tenant isolationRow-level security in the database plus a verified tenant on every requestCurrent controls described in the security questionnaire
EncryptionTLS in transit. Encryption at rest is on our roadmap and not yet in placeStated plainly in our security questionnaire
RBACLane-aware (PE/PC/RE), position-scoped, artifact-scoped (memo/scenario/export)Mirrors how investment teams actually operate
Audit logsOverride trail, share-token log, IC anchor event log, action ownership trailStreamable to your SIEM
Deployment isolationMulti-tenant service on a dedicated server in Germany; a dedicated instance per institution is plannedHosting details in the security package

Have a security checklist?

We map your controls to ours concretely — provenance chain, signed exports, audit log shape, isolation model. No vague promises.