Skip to content

AVISE · A HOUSE FOR YOUR FIRM'S DEAL FLOW

§ 00 · SECURITY

What we can prove, and what we cannot.

A buyer told us three times in one call that he would not be comfortable putting his firm's data into a system like this. Fair, for a young company. This page is the answer, and it leads with the part most vendors bury.

§ 01 · CERTIFICATION

Certifications, and who actually holds them.

CERTIFICATION STATUS

Avise has SOC 2 Type I in progress, with Type II intended to follow. Our sub-processors are SOC 2 Type II certified in their own right. That is their certification of their platforms, and we do not present it as ours.

A vendor who says that running on certified infrastructure makes them certified has turned that sentence around to sound like approval. We will not. Where a certification is a hard gate in your policy, ask us on the first call and you will get the current status in writing rather than a roadmap.

Who holds which certification, and what each is used for. The Type II certifications belong to the sub-processors, not to Avise. Named sub-processors are listed in the DPA, which we send on request.

PARTY

Avise

CERTIFICATION
SOC 2 Type I in progress; Type II intended to follow.
WHAT IT COVERS
Nothing on this page is an audited control. It describes how the product is built, so you can test it yourself.

PARTY

Cloud platform

CERTIFICATION
SOC 2 Type II, theirs not ours.
WHAT IT COVERS
Database, file storage, authentication, application hosting and delivery.

PARTY

Document and language models

CERTIFICATION
SOC 2 Type II, theirs not ours.
WHAT IT COVERS
Layout and table extraction, reading document text, drafting memo sections.

WHAT WE WILL SEND YOU INSTEAD

A data processing agreement (DPA), the current sub-processor list, the deletion procedure, and a written answer to your own questionnaire, from a person who can be held to it, not a portal that generates a page of ticks.

§ 02 · ISOLATION

“You work with other firms. Can you see our deal flow?”

No. Every organisation is a separate tenant and every request is scoped to the organisation making it. No shared workspace, no cross-firm view, no internal dashboard showing one firm's pipeline to another.

01

Tenant boundary

Records belong to an organisation. Access is checked against the organisation on the request, not a document identifier somebody might guess or a link that might be forwarded.

02

404, not 403

A request for another organisation’s record returns a 404, as if it does not exist, rather than a 403 confirming it does. Refusals leak: they tell an attacker they found something real.

03

No cross-firm inference

Nothing you upload informs another customer’s deal, and no benchmark, model or index is built across firms. If we ever proposed one it would be opt-in, in writing.

§ 03 · ACCESS

Inside your own firm, access is not all or nothing.

Two layers. A role sets what somebody can do across the organisation; deal team membership sets which deals they touch. The second layer is what matters when two mandates in one sector run side by side.

The four organisation roles in Avise and what each is for.

ROLE

Administrator

WHAT IT IS FOR
Manages the organisation, its people and their roles.

ROLE

Member

WHAT IT IS FOR
Does the work (deals, documents, contacts, memos) within the deals they are on.

ROLE

Viewer

WHAT IT IS FOR
Reads without changing anything. For the partner who wants the state of play and nothing else.

ROLE

Operations

WHAT IT IS FOR
Keeps the house in order: imports, exports, housekeeping across the pipeline.

Per-deal membership sits on top of the role, so somebody can be a full member of the firm and still see only the deals they are working on.

§ 04 · AUDIT

A log nobody can quietly tidy up.

The audit log is insert-only: entries are written and never edited or deleted, including by us. It covers more than twenty-five event types and is retained for two years.

01

What it records

Who did what, to which record, and when, across documents, deals, contacts, access changes and exports. The same record answers “when did we send the agreement” and “who opened this folder”.

02

Why insert-only matters

A log that can be edited proves nothing. This one cannot be rewritten after the fact, which is the only property that makes it worth anything in a dispute.

03

Getting it out

Audit log export is published as part of the Enterprise plan. If you need the log in your own systems, price that plan rather than assuming the capability sits underneath a cheaper one.

§ 05 · DATA

Where it sits, and how you get it back.

RESIDENCY

Data is hosted in the United States. There is no EU, UK, India or Gulf region today, and no on-premise or bring-your-own-cloud deployment.

If your mandate or regulator requires data in a particular jurisdiction, Avise cannot meet that today. A straight no, not a roadmap.

ENCRYPTION

Traffic runs over TLS. Data at rest (database records and uploaded files alike) is encrypted by the managed platforms that hold it.

We do not operate a customer-managed key scheme, and we are not going to describe one we do not have.

DELETION AND EXPORT

Deletion is supported. The DPA covers the GDPR position, including deletion and the sub-processor list.

Everything you put in comes back out: pipeline and contacts as CSV, memos exported, documents downloaded.

WHAT WE ASK OF YOU

Test it before you trust it: create a second organisation, try to reach the first one’s records, watch the 404 come back, then read the audit log. Security claims are worth what you can verify.

§ 06 · DOCUMENTS AND AI

Your documents are read by third-party models.

The part a security review cares about most, and the part most vendors describe vaguely. Reading a CIM means sending its contents to a model. No configuration today avoids that.

01

Who processes what

Document contents are processed by two specialist sub-processors: one for layout and table extraction, the other for reading text and drafting memo sections. Both are SOC 2 Type II certified in their own right, and both are named in the DPA, which we send on request rather than publish here.

02

What we do not do with it

We do not train models. Avise builds none of its own and fine-tunes nothing on your documents, so there is no mechanism by which one firm’s CIM could surface in another’s output. The sub-processors’ own terms come with the DPA rather than paraphrased here.

03

What stays inside

Documents are stored in your organisation’s storage and served through the same access checks as everything else. Extracted figures, analysis and memos live on the deal, inside the tenant boundary above.

04

If that is a blocker

Some firms cannot send client documents to a third-party model at all. Say so on the first call. There is no local-model or private-deployment option today, and we would rather lose the meeting than have a security review find it in week three.

§ 07 · OPEN ITEMS

Everything on this list is a gap, written down by us.

A security page that contains only good news is a marketing page. This is the rest of it.

  1. 01

    SOC 2 Type I is in progress

    Not finished. When the report exists we will say so here, with its date and scope, and send it under an NDA rather than put a badge on a homepage.

  2. 02

    There is no on-premise or bring-your-own-cloud option

    Everything runs in the United States. A firm whose mandate requires data in a particular jurisdiction, or on its own infrastructure, cannot be served today. Not shipped, so not sold.

  3. 03

    We do not publish a penetration test

    There is no third-party test report to give you. When there is one it will be listed here with its date.

  4. 04

    Encryption keys are not customer-managed

    Data at rest is encrypted by the platforms that hold it. We do not operate a customer-managed key scheme, and will not describe one we do not have.

  5. 05

    SSO sits on one plan

    SSO and audit log export are published as part of the Enterprise plan. If your security policy requires SSO, price that plan rather than a cheaper one.

  6. 06

    We publish certifications only when they exist

    No compliance badge appears on this site that an auditor has not issued. Where our providers hold certifications, we name them as theirs, never as ours.

If something here is the reason you cannot proceed, tell us and we will say whether it is weeks away or not on the plan at all. Write to hello@pocket-fund.com, or read how the product actually works on the product page.

§ 08 · NEXT

Send us your security questionnaire before the demo.

We would rather answer in writing first and have the call be about the deal work. Where the honest answer is “not yet”, it will say “not yet”.