Tenant boundary
Records belong to an organisation. Access is checked against the organisation on the request, not a document identifier somebody might guess or a link that might be forwarded.
AVISE · A HOUSE FOR YOUR FIRM'S DEAL FLOW
§ 00 · SECURITY
A buyer told us three times in one call that he would not be comfortable putting his firm's data into a system like this. Fair, for a young company. This page is the answer, and it leads with the part most vendors bury.
§ 01 · CERTIFICATION
CERTIFICATION STATUS
Avise has SOC 2 Type I in progress, with Type II intended to follow. Our sub-processors are SOC 2 Type II certified in their own right. That is their certification of their platforms, and we do not present it as ours.
A vendor who says that running on certified infrastructure makes them certified has turned that sentence around to sound like approval. We will not. Where a certification is a hard gate in your policy, ask us on the first call and you will get the current status in writing rather than a roadmap.
Who holds which certification, and what each is used for. The Type II certifications belong to the sub-processors, not to Avise. Named sub-processors are listed in the DPA, which we send on request.
PARTY
Avise
PARTY
Cloud platform
PARTY
Document and language models
| PARTY | CERTIFICATION | WHAT IT COVERS |
|---|---|---|
| Avise | SOC 2 Type I in progress; Type II intended to follow. | Nothing on this page is an audited control. It describes how the product is built, so you can test it yourself. |
| Cloud platform | SOC 2 Type II, theirs not ours. | Database, file storage, authentication, application hosting and delivery. |
| Document and language models | SOC 2 Type II, theirs not ours. | Layout and table extraction, reading document text, drafting memo sections. |
WHAT WE WILL SEND YOU INSTEAD
A data processing agreement (DPA), the current sub-processor list, the deletion procedure, and a written answer to your own questionnaire, from a person who can be held to it, not a portal that generates a page of ticks.
§ 02 · ISOLATION
No. Every organisation is a separate tenant and every request is scoped to the organisation making it. No shared workspace, no cross-firm view, no internal dashboard showing one firm's pipeline to another.
Records belong to an organisation. Access is checked against the organisation on the request, not a document identifier somebody might guess or a link that might be forwarded.
A request for another organisation’s record returns a 404, as if it does not exist, rather than a 403 confirming it does. Refusals leak: they tell an attacker they found something real.
Nothing you upload informs another customer’s deal, and no benchmark, model or index is built across firms. If we ever proposed one it would be opt-in, in writing.
§ 03 · ACCESS
Two layers. A role sets what somebody can do across the organisation; deal team membership sets which deals they touch. The second layer is what matters when two mandates in one sector run side by side.
The four organisation roles in Avise and what each is for.
ROLE
Administrator
ROLE
Member
ROLE
Viewer
ROLE
Operations
| ROLE | WHAT IT IS FOR |
|---|---|
| Administrator | Manages the organisation, its people and their roles. |
| Member | Does the work (deals, documents, contacts, memos) within the deals they are on. |
| Viewer | Reads without changing anything. For the partner who wants the state of play and nothing else. |
| Operations | Keeps the house in order: imports, exports, housekeeping across the pipeline. |
Per-deal membership sits on top of the role, so somebody can be a full member of the firm and still see only the deals they are working on.
§ 04 · AUDIT
The audit log is insert-only: entries are written and never edited or deleted, including by us. It covers more than twenty-five event types and is retained for two years.
Who did what, to which record, and when, across documents, deals, contacts, access changes and exports. The same record answers “when did we send the agreement” and “who opened this folder”.
A log that can be edited proves nothing. This one cannot be rewritten after the fact, which is the only property that makes it worth anything in a dispute.
Audit log export is published as part of the Enterprise plan. If you need the log in your own systems, price that plan rather than assuming the capability sits underneath a cheaper one.
§ 05 · DATA
RESIDENCY
Data is hosted in the United States. There is no EU, UK, India or Gulf region today, and no on-premise or bring-your-own-cloud deployment.
If your mandate or regulator requires data in a particular jurisdiction, Avise cannot meet that today. A straight no, not a roadmap.
ENCRYPTION
Traffic runs over TLS. Data at rest (database records and uploaded files alike) is encrypted by the managed platforms that hold it.
We do not operate a customer-managed key scheme, and we are not going to describe one we do not have.
DELETION AND EXPORT
Deletion is supported. The DPA covers the GDPR position, including deletion and the sub-processor list.
Everything you put in comes back out: pipeline and contacts as CSV, memos exported, documents downloaded.
WHAT WE ASK OF YOU
Test it before you trust it: create a second organisation, try to reach the first one’s records, watch the 404 come back, then read the audit log. Security claims are worth what you can verify.
§ 06 · DOCUMENTS AND AI
The part a security review cares about most, and the part most vendors describe vaguely. Reading a CIM means sending its contents to a model. No configuration today avoids that.
Document contents are processed by two specialist sub-processors: one for layout and table extraction, the other for reading text and drafting memo sections. Both are SOC 2 Type II certified in their own right, and both are named in the DPA, which we send on request rather than publish here.
We do not train models. Avise builds none of its own and fine-tunes nothing on your documents, so there is no mechanism by which one firm’s CIM could surface in another’s output. The sub-processors’ own terms come with the DPA rather than paraphrased here.
Documents are stored in your organisation’s storage and served through the same access checks as everything else. Extracted figures, analysis and memos live on the deal, inside the tenant boundary above.
Some firms cannot send client documents to a third-party model at all. Say so on the first call. There is no local-model or private-deployment option today, and we would rather lose the meeting than have a security review find it in week three.
§ 07 · OPEN ITEMS
A security page that contains only good news is a marketing page. This is the rest of it.
Not finished. When the report exists we will say so here, with its date and scope, and send it under an NDA rather than put a badge on a homepage.
Everything runs in the United States. A firm whose mandate requires data in a particular jurisdiction, or on its own infrastructure, cannot be served today. Not shipped, so not sold.
There is no third-party test report to give you. When there is one it will be listed here with its date.
Data at rest is encrypted by the platforms that hold it. We do not operate a customer-managed key scheme, and will not describe one we do not have.
SSO and audit log export are published as part of the Enterprise plan. If your security policy requires SSO, price that plan rather than a cheaper one.
No compliance badge appears on this site that an auditor has not issued. Where our providers hold certifications, we name them as theirs, never as ours.
If something here is the reason you cannot proceed, tell us and we will say whether it is weeks away or not on the plan at all. Write to hello@pocket-fund.com, or read how the product actually works on the product page.
§ 08 · NEXT
We would rather answer in writing first and have the call be about the deal work. Where the honest answer is “not yet”, it will say “not yet”.