Security

Security and data protection at Bright Capital America

This page describes the controls we actually operate. We do not display compliance badges or certification marks we have not earned.

How your data is protected

Role-based access control

Every workspace member holds an explicit role — owner, administrator, member or read-only. Features and data are gated on that role, and permission checks are enforced on the server, not in the browser.

Row-level database security

Access rules are enforced in the database itself, per row, so a request can only ever read or write records belonging to a workspace the signed-in user is a member of. Workspaces are isolated from one another by default.

Private, permissioned file storage

Document-request uploads, group documents, branding assets and pitch decks live in private storage buckets. There are no public file URLs; each download is authorized against the requesting user's role at the moment of access.

Step-up verification for sensitive actions

Sensitive equity operations — such as viewing private stakeholder identifiers or exporting records — require explicit equity authority and a fresh identity re-verification, separate from ordinary workspace administration.

Audit trails

Equity ledger entries are append-only, and administrative and security-relevant actions are recorded with actor, entity and timestamp so activity can be reconstructed after the fact.

Encryption in transit and at rest

The platform is served over HTTPS with a valid certificate on brightcapital.fund, and application data and uploaded files are encrypted at rest by our infrastructure provider.

Exactly what data we store

Data is encrypted in transit with TLS and at rest with AES-256 by our infrastructure provider. Below is what actually sits in the account.

Account and profile data

Name, work email, the workspaces you belong to and your role in each. Passwords are never stored by us — sign-in is handled by our authentication provider, and social sign-in stores only the identifier it returns.

Workspace records you create

Company and investor profiles, pipeline and CRM entries, cap-table and stakeholder records, fund records, notes and tasks. These are readable only by members of that workspace.

Uploaded documents

Pitch decks, data-room files, group documents and branding assets, held in private storage with no public URLs. We do not use your documents to train models.

Billing data

Plan, status and subscription identifiers only. Card numbers never reach our servers — payments are processed by Stripe and we store no card or bank details.

Sensitive identifiers in company formation

Where a filing requires an SSN, ITIN or EIN, it is collected on an encrypted field, never placed in a URL, log, email or profile, and is visible only to the staff processing that filing.

Operational logs

Request, security and administrative-action logs with actor, entity and timestamp. Logs are scrubbed of sensitive identifiers and are retained for troubleshooting and audit only.

What we are responsible for

  • Keeping the platform available, patched and encrypted in transit and at rest.
  • Enforcing workspace isolation and role permissions on the server.
  • Recording administrative and security-relevant actions with actor and timestamp.
  • Telling you promptly, in writing, if your data is affected by a security incident.
  • Deleting your workspace data on request, and on account closure.

What you are responsible for

  • Who you invite into a workspace and the role you give them.
  • Turning on two-factor authentication for your account and your team.
  • Which documents you place in a data room and who you grant access to.
  • The accuracy and legality of records you upload, including personal data of others.
  • Your own diligence: we do not verify third parties or guarantee any outcome.

Certifications: where we actually stand

Bright Capital America does not hold SOC 2, ISO 27001, PCI DSS or any other third-party security certification, and we make no claim of GDPR, HIPAA or PCI compliance. We have removed every badge and marketing claim of that kind from this site. If a formal attestation is a requirement for your organization, contact us and we will tell you honestly where we are and what we can commit to in writing.

Email authentication

  • SPF, DKIM and DMARC are published and passing for brightcapital.fund.
  • Platform email is sent from an authenticated sending domain, with replies directed to support@brightcapital.fund.
  • Bounce and complaint suppression is applied automatically before any send.

What Bright Capital America does not do

  • We do not execute investments, accept capital commitments, move money, form SPVs or operate a secondary market. Bright Capital America is subscription software for running private-capital workflows.
  • We do not sell customer data, and we do not use your uploaded documents to train models.
  • We do not publish customer names, logos or quotes without written authorization.

Reporting a vulnerability

If you believe you have found a security issue, email support@brightcapital.fund with the steps to reproduce it. Please give us a reasonable window to investigate before disclosing publicly, and do not access or modify data that is not your own. We acknowledge reports and keep you updated until the issue is resolved.

Contact our team

United States Office (Head Office)3911 Concord Pike, 8030Wilmington, DE 19803United States
Canada Office1270 Central Parkway West, Suite 120Mississauga, Ontario L5C 4P4Canada

Phone support: +1 (302) 439-7848

Email: support@brightcapital.fund

Please call or email us, and our team will respond as soon as possible.