Security

How your data room is protected

This page describes what is actually built today, plainly, without borrowing the language of a certification we do not hold. It is a working draft — if you are evaluating RaisePortal for your own diligence, ask us anything it does not answer.

Draft notice. RaisePortal does not currently hold SOC 2, ISO 27001 or any third-party security certification, and does not currently offer a signed GDPR data processing addendum. Nothing on this page should be read as a compliance attestation. It is an honest account of the engineering controls in place as the product is being built.

Every request is tenant-scoped

Every database query that touches your documents, your team, your raise or your investor views is written against your startup_id — never a bare record ID on its own. One founder's portal cannot read another's rows by guessing or changing an ID in a request.

Passwords

Account passwords are hashed with Argon2id before they are stored — we never store, log, or put a plaintext password in a URL or a query string. A failed sign-in does not reveal whether the email address on the account exists: a wrong password and an unknown email return the exact same message, in the same amount of time. Repeated failed attempts from the same address are rate-limited.

Sessions

Signed-in sessions are stored server-side in Redis, not in the cookie itself — the cookie holds only an identifier, marked HttpOnly, Secure and SameSite=Lax. That cookie is scoped to work across every portal's subdomain, which is what makes staying signed in convenient — so every request also checks, on the server, that the session actually belongs to the portal being requested. A session created on one portal is never accepted as authentication on another, even though the browser will send the same cookie to both.

Cross-site request forgery

Every form that changes something — signing up, signing in, signing out — carries a one-time token tied to your own browser session, checked on the server before anything happens. A page on another site cannot submit one of these forms on your behalf, even if it tricks your browser into trying.

Data in transit

The application connects to its database over an encrypted connection. RaisePortal is served over HTTPS only.

What is not built yet

Being direct about gaps is part of being honest about the ones we've closed. Documents, private-document filtering, per-tenant file storage and investor rooms have not shipped yet — this section will be replaced with a real description the day they do, not before. Also not yet shipped: malware scanning on uploads, PDF watermarking, two-factor authentication, and a formal audit log of privileged actions. All are on the build plan.

Report a problem

Found something that looks like a security issue? Please tell us before telling anyone else: [email protected]. We will acknowledge reports and are still defining a formal disclosure timeline (placeholder — response-time commitment not yet set).