Decision integrity is a security property.
Private markets run on sensitive documents and high-stakes decisions. The risk is not just confidentiality — it is silent error: definition drift, provenance loss, decisions that can't be defended later. Capital Refinery treats every figure, every export, and every IC approval as a verifiable artifact.
Why each control matters.
Decision integrity
Security includes preventing silent error.
Definition drift between deals. Provenance loss across teams. Black-box outputs that cannot be defended at IC or audit. Capital Refinery builds against those failure modes structurally — not as an afterthought.
Least privilege by default
Access mirrors how the firm works.
Role-based access aligned to deal workflows. Tenant boundaries enforced. Lane-aware visibility (PE vs PC vs RE). Per-position scope. Override audit trail per figure. Cross-deal leakage prevented at the platform layer, not at policy.
Deployment flexibility
Real procurement constraints supported.
Managed SaaS for most teams. Single-tenant, VPC, and stricter network isolation for institutional procurement. Encryption-aware document handling. Audit logs to your SIEM. Match the security posture, not vendor convenience.
What Capital Refinery does — concretely.
| Capability | What it does | Capital Refinery |
|---|---|---|
| Provenance-signed exports | Every docx and xlsx carries a cryptographic fingerprint. The LP can verify independently that the report matches what came out of the IC system at approval. | Defensible LP and audit. Eliminates “is this the version we approved” ambiguity. |
| IC anchor immutability | Every IC approval writes a cryptographic snapshot of the full decision basis. The anchor cannot be backdated or rewritten. | Decision accountability. The basis at approval is reconstructable forever. |
| Share-token audit log | Every LP-share token issuance is logged with principal, IP, user-agent, and token hash. Raw tokens never persisted. | Who saw what, when. Compliance check on demand. |
| Source-document lineage | Every figure in the system clicks back to the source document, page, and cell. Filename chips on Decision Timeline are click-through navigable. | “Where did this number come from” has a deterministic answer. |
| Override audit trail | Every analyst override of a figure or assumption is recorded with principal, basis, and timestamp. | No silent modifications. Audit reconstructs every override. |
| RBAC by lane and position | Role and permission scoped to lane (PE/PC/RE), to position, and to artifact (memo, scenario, export). | Aligns access to how investment teams actually operate. |
| Deployment options | Managed SaaS, single-tenant, VPC, stricter isolation for institutional posture. | Matches firm risk posture and procurement constraints. |
Security review ready?
If you have a checklist, we map controls and deployment options concretely — provenance chain, signed exports, audit log shape, isolation model. No vague promises.