Fund managers trust Proteus One with their most confidential documents — PPMs, financials, subscription agreements, trade secrets. We built every layer of our platform to honour that trust. Where a control is on the roadmap rather than in production, this page says so — you should not have to discover it in diligence.
AES-256 encryption at rest across the database and document storage
Provided by our managed infrastructure (Supabase, eu-central-1). Credentials we hold on your behalf — mailbox OAuth tokens, CRM tokens — get a second layer of AES-256-GCM encryption in the application before they are written.
TLS encryption in transit
All traffic between your browser and our servers, and between our servers and every third-party API, runs over TLS.
EU data residency (Frankfurt)
Your data is stored in Supabase-managed infrastructure in Frankfurt, Germany (eu-central-1).
PostgreSQL row-level security scopes every query to your workspace
Each request sets the tenant context before it touches the database, and database-level policies restrict reads and writes to rows belonging to that workspace.
One application-layer encryption key, held outside the database
We use a single deployment-wide key rather than per-tenant keys today, and it never sits in the database beside the data it protects. Envelope encryption with a managed KMS is on our roadmap — ask us where it stands before you send us anything you would not send by email.
Your documents are never used to train models
Drafting, scoring, and DDQ answers are generated through the Anthropic API, whose commercial terms state that inputs and outputs are not used to train their models. We add no training pipeline of our own.
Every request is stateless
We hold no vendor-side session or conversation state. Each request carries only the context needed to answer it, and nothing persists at the provider between requests.
No cross-workspace context mixing — ever
Workspace boundaries are enforced when the context for a request is assembled, so one tenant’s documents can never reach another tenant’s draft.
Anthropic is our only model subprocessor; OpenAI generates search embeddings
Named plainly so your ops team can diligence them directly. We do not currently hold a zero-retention addendum with either provider — if that is a requirement for you, tell us before you upload anything sensitive.
Every workspace is fully isolated from every other
Each account today is a single-seat workspace. Multi-seat workspaces with Owner / Admin / Member / Viewer roles are in development — until they ship, nobody outside your account can see your data, and role names you may see in the product are not yet enforced as permissions.
Authentication is handled by Clerk
Email and Google sign-in, with multi-factor authentication available through Clerk. We never store your password.
Mailbox access is delegated, revocable OAuth
Connecting Gmail or Outlook grants scoped OAuth tokens which we encrypt at rest. Disconnect from Settings, or revoke from Google or Microsoft directly, and our access ends immediately.
SSO/SAML and IP allowlisting are not available yet
Both are on the roadmap for enterprise contracts. If your identity or network policy requires them, tell us before you sign rather than after.
SOC 2 Type II — readiness in progress, no report issued yet
We are doing the readiness work and have not been audited. There is no SOC 2 report to send you today, and we will not imply otherwise. Ask us and we will share our current security questionnaire and where the programme actually stands.
GDPR — EU residency, data processing terms, and erasure on request
Infrastructure is EU-hosted, and we action erasure requests directly. Request our DPA before you upload investor personal data.
Reg D framing is built into drafting, not enforced as review
506(b) and 506(c) constraints shape how outreach is drafted — no general solicitation in 506(b) mode, no return guarantees in either. This is drafting guidance, not a compliance review, and it does not replace your compliance officer or counsel.
Audit log of security-relevant events
Workspace provisioning, mailbox connect and disconnect, CRM connect and disconnect, unsubscribes, and deletions are written to a timestamped audit log that the product only ever appends to. It is not yet a complete record of every action, and we do not currently offer it as a customer-facing export.
You own your data. Always.
Proteus One claims no ownership or licence over what you upload or over anything the product drafts for you.
Data export on request (GDPR Article 20)
Ask and we will produce your documents, investors, and campaign history in standard formats. Self-service export from the product is on the roadmap — today a person on our side runs it for you.
Deletion on request, with no retention period of our own
Deleting removes the record from the live product immediately. Copies persist only in our hosting provider’s encrypted backups until those roll off on their own schedule — we do not keep separate archives.
Custom retention windows are contract-scoped, not self-service
There is no retention-policy setting in the product yet. Enterprise retention requirements are agreed and implemented as part of the contract.
We answer diligence questions and complete security questionnaires directly — including the ones where the honest answer is “not yet”. Write to us and a founder will reply.
security@ravenraise.com