Security at PocketFund

Founder data is the most sensitive on the platform.

Cap tables, financial models, term sheets — we treat them with the same controls a Tier-1 bank would.

What we do, in plain English.

HTTPS everywhere

TLS 1.3 + HSTS on every page. HTTP traffic is auto-redirected to HTTPS. Certificates issued automatically by Let's Encrypt via Vercel.

Encryption at rest

Postgres databases (Supabase) and object storage are encrypted at rest by default by our infrastructure providers.

Row-level security

Every database table is gated by row-level security policies — your data is only readable by your account, the counterparty in a deal, or a granted reviewer.

NDA-gated data rooms

Founder data rooms require investor NDA acceptance before access. Every view is logged and timestamped. Founders can revoke access with one click.

Audit log

Sensitive actions (NDA signings, data-room file views, bid placements) are recorded in an append-only audit log.

MFA available

Two-factor authentication available on every account. We strongly recommend enabling it on the first login.

Responsible disclosure

Found a vulnerability? Email security@pocketfund.in. We acknowledge within 72 hours and credit responsible reports.

Honest about where we are.

🌐GDPR best practicesEU/UK data-subject rights honoured (access, deletion, portability)
🇮🇳DPDP Act 2023India — purpose-limited processing, consent-based, breach notification
🍃Data minimisationWe collect only what we need to match founders and investors
Retention limitsAccount data: until you delete · Tax records: 7 years (legal req.)

No certification claims. PocketFund is a young company. We're committed to following GDPR + DPDP best practices but are not yet SOC 2 / ISO 27001 audited. As we grow, we'll pursue formal certifications and update this page when each completes — not before.

Found a vulnerability? Tell us.

We run a responsible-disclosure program. Email security@pocketfund.in with details of the issue, steps to reproduce, and your PGP key (if any). We'll acknowledge within 24 hours, triage within 72 hours, and credit you in our hall of fame on resolution. We pay bug bounties for verified vulnerabilities — see the policy on the contact page.