Capital Refinery
Security & Trust

Decision integrity is a security property.

Private markets run on sensitive documents and high-stakes decisions. The risk is not just confidentiality — it is silent error: definition drift, provenance loss, decisions that can't be defended later. Capital Refinery treats every figure, every export, and every IC approval as a verifiable artifact.

What we optimize for

Why each control matters.

01

Decision integrity

Security includes preventing silent error.

Definition drift between deals. Provenance loss across teams. Black-box outputs that cannot be defended at IC or audit. Capital Refinery builds against those failure modes structurally — not as an afterthought.

02

Least privilege by default

Access mirrors how the firm works.

Role-based access aligned to deal workflows. Tenant boundaries enforced. Lane-aware visibility (PE vs PC vs RE). Per-position scope. Override audit trail per figure. Cross-deal leakage prevented at the platform layer, not at policy.

03

Deployment flexibility

Real procurement constraints supported.

Managed SaaS for most teams. Single-tenant, VPC, and stricter network isolation for institutional procurement. Encryption-aware document handling. Audit logs to your SIEM. Match the security posture, not vendor convenience.

Controls map

What Capital Refinery does — concretely.

CapabilityWhat it doesCapital Refinery
Provenance-signed exportsEvery docx and xlsx carries a cryptographic fingerprint. The LP can verify independently that the report matches what came out of the IC system at approval.Defensible LP and audit. Eliminates “is this the version we approved” ambiguity.
IC anchor immutabilityEvery IC approval writes a cryptographic snapshot of the full decision basis. The anchor cannot be backdated or rewritten.Decision accountability. The basis at approval is reconstructable forever.
Share-token audit logEvery LP-share token issuance is logged with principal, IP, user-agent, and token hash. Raw tokens never persisted.Who saw what, when. Compliance check on demand.
Source-document lineageEvery figure in the system clicks back to the source document, page, and cell. Filename chips on Decision Timeline are click-through navigable.“Where did this number come from” has a deterministic answer.
Override audit trailEvery analyst override of a figure or assumption is recorded with principal, basis, and timestamp.No silent modifications. Audit reconstructs every override.
RBAC by lane and positionRole and permission scoped to lane (PE/PC/RE), to position, and to artifact (memo, scenario, export).Aligns access to how investment teams actually operate.
Deployment optionsManaged SaaS, single-tenant, VPC, stricter isolation for institutional posture.Matches firm risk posture and procurement constraints.

Security review ready?

If you have a checklist, we map controls and deployment options concretely — provenance chain, signed exports, audit log shape, isolation model. No vague promises.