Security & Architecture

How Vantage handles
your most sensitive data.

Institutional capital allocators trust Vantage with founder update letters, valuation analyses, capital calls, and personal investment data. The principles below describe how we hold that data and what we will not do with it.

Trust Center

Proof, not just principles.

The formal evidence portal behind everything on this page. Continuously monitored, traceable to source, and built to clear a security review without a sales call.

Monitored controls · Frameworks · Document requests · Subprocessors · FAQ

AttestationsCurrent
SOC 2 Type I
AICPA · VIA MINDSTUDIO
SOC 2 Type II
AICPA · VIA MINDSTUDIO
GDPR
EU · COMPLIANT
+ 36 monitored controls · 6 domains
Operating Principles

What we will not do
with your data.

Sophisticated buyers care about what we don't do as much as what we do. These commitments are baked into the product, not policy that can be quietly revised.

No model training
Vantage does not train models on customer data. Founder updates, valuation letters, and personal investment data flow through inference only pipelines. No fine tuning, no embedding training, no transfer to model providers' training corpora. Period.
No data sale
Vantage does not sell customer data, share it with third party data brokers, or use it to power benchmarking products consumed by other customers without explicit opt in.
No third party trackers
The Vantage marketing site and product run with zero third party analytics, advertising trackers, or session replay tools. Page views are counted server side. No Google Analytics, no Hotjar, no Segment, no Meta pixel.
Customer controlled deletion
Customers can request a full data export and irreversible deletion at any time. We delete within 30 days of a verified request, including replicas and backups, on a documented timeline.
System Architecture

How a document
flows through Vantage.

Every customer document, whether a founder update, valuation letter, or capital call notice, passes through five layers, each with its own boundary. Customer data never leaves the customer's tenant.

01 · Ingest
Customer email forwarderSFTP dropDirect upload (UI)API (TLS 1.3)
02 · Tenant Isolation
Per tenant namespaceEncrypted at rest (AES-256)RBAC enforced at storage layer
03 · Extraction (inference only)
Anthropic (zero retention)OpenAI (zero retention)Google Gemini (zero retention)In house OCR/vision pipelines
04 · Application Logic
Method level RBACScoped data accessPer action audit logIdempotency & retry safety
05 · Audit Log (append only)
Every read & write recordedCustomer exportableTamper evident
Certifications & Standards

Audited, attested, and
designed for compliance review.

Vantage runs on the SOC 2 Type I and Type II certified MindStudio platform and inherits its certified infrastructure. The reports and agreements below are shared with reviewers under NDA.

SOC 2 (Platform)
Current. Vantage is built on MindStudio, which holds SOC 2 Type I and Type II certification. The platform report is available under NDA on request.
SOC 2 (Vantage)
In progress. Vantage's own organizational attestation, layered on the certified platform. Type I issued Q2 2026; Type II target Q3 2026.
ISO 27001
Targeted alongside SOC 2 Type II. Information security management system documented and operational; certification audit Q4 2026.
GDPR & CCPA
Compliant. DPAs available on request. EU customer data hosted in EU regions; California opt out flows in place.
Penetration Testing
Annual third party penetration testing. Latest report (Q1 2026) available under NDA. Findings remediated within agreed SLAs.
Authentication & Access
Passwordless email verification sign in. Role based access control with strict per tenant isolation. Customer administrators provision, deprovision, and assign roles for every user in their firm.
Data Residency & Hosting

Where your data lives.

Primary Hosting
AWS us-east-1 (default). EU customers: AWS eu-west-2 (London) available; UK and US data segregation enforced at infrastructure level.
Encryption
In transit: TLS 1.3 with mutual auth on all API endpoints. At rest: AES-256 with per tenant key isolation. Key rotation: 90 day automatic.
Backups
Continuous replication to a secondary region. Point in time recovery to any moment within the past 30 days. Backup encryption with separate key material.
Sub Processors
Public list of every third party sub processor available at /privacy. Customers notified 30 days before any sub processor change.