Role-based access control
Every workspace member holds an explicit role — owner, administrator, member or read-only. Features and data are gated on that role, and permission checks are enforced on the server, not in the browser.
Security
This page describes the controls we actually operate. We do not display compliance badges or certification marks we have not earned.
Every workspace member holds an explicit role — owner, administrator, member or read-only. Features and data are gated on that role, and permission checks are enforced on the server, not in the browser.
Access rules are enforced in the database itself, per row, so a request can only ever read or write records belonging to a workspace the signed-in user is a member of. Workspaces are isolated from one another by default.
Document-request uploads, group documents, branding assets and pitch decks live in private storage buckets. There are no public file URLs; each download is authorized against the requesting user's role at the moment of access.
Sensitive equity operations — such as viewing private stakeholder identifiers or exporting records — require explicit equity authority and a fresh identity re-verification, separate from ordinary workspace administration.
Equity ledger entries are append-only, and administrative and security-relevant actions are recorded with actor, entity and timestamp so activity can be reconstructed after the fact.
The platform is served over HTTPS with a valid certificate on brightcapital.fund, and application data and uploaded files are encrypted at rest by our infrastructure provider.
Data is encrypted in transit with TLS and at rest with AES-256 by our infrastructure provider. Below is what actually sits in the account.
Name, work email, the workspaces you belong to and your role in each. Passwords are never stored by us — sign-in is handled by our authentication provider, and social sign-in stores only the identifier it returns.
Company and investor profiles, pipeline and CRM entries, cap-table and stakeholder records, fund records, notes and tasks. These are readable only by members of that workspace.
Pitch decks, data-room files, group documents and branding assets, held in private storage with no public URLs. We do not use your documents to train models.
Plan, status and subscription identifiers only. Card numbers never reach our servers — payments are processed by Stripe and we store no card or bank details.
Where a filing requires an SSN, ITIN or EIN, it is collected on an encrypted field, never placed in a URL, log, email or profile, and is visible only to the staff processing that filing.
Request, security and administrative-action logs with actor, entity and timestamp. Logs are scrubbed of sensitive identifiers and are retained for troubleshooting and audit only.
Bright Capital America does not hold SOC 2, ISO 27001, PCI DSS or any other third-party security certification, and we make no claim of GDPR, HIPAA or PCI compliance. We have removed every badge and marketing claim of that kind from this site. If a formal attestation is a requirement for your organization, contact us and we will tell you honestly where we are and what we can commit to in writing.
If you believe you have found a security issue, email support@brightcapital.fund with the steps to reproduce it. Please give us a reasonable window to investigate before disclosing publicly, and do not access or modify data that is not your own. We acknowledge reports and keep you updated until the issue is resolved.
Phone support: +1 (302) 439-7848
Email: support@brightcapital.fund
Please call or email us, and our team will respond as soon as possible.