Home
Who We Serve
About Contact Setup a Demo
Security & Trust

Built for data you cannot afford to lose.

CapHive holds capital accounts, investor identity documents and unpublished valuations. This page sets out how that data is protected, who can reach it, and what your fund controls.

SOC 2 Type II
AES-256 at rest · TLS 1.3 in transit
ISO 27001:2022
SSO / OAuth & full audit logs
Controls

Six domains, described plainly.

Security on a fund platform is not one feature. It is a set of controls that have to hold together — encryption, identity, logging, infrastructure, recovery and the way software gets built.

Encryption

Data is encrypted in transit between you and the platform, and encrypted at rest in storage and backups. Encryption keys are managed separately from the data they protect.

Access control and identity

Role-based access control decides what each user can see and do, down to the fund and the record type. Multi-factor authentication is supported, and access is reviewed when roles change.

Audit logging

Actions that change a record are logged with the user, the time and the before-and-after value — in the interface and through the API. When an auditor asks how a number was produced, the answer is a query rather than a reconstruction.

Infrastructure and hosting

The platform runs on managed cloud infrastructure, with environments separated and administrative access restricted to a small, named group. Production access requires an approved reason.

Backup and recovery

Data is backed up on a schedule, backups are encrypted, and restores are tested rather than assumed. Recovery objectives are documented and shared with clients who ask.

Secure development and vulnerabilities

Changes are peer reviewed before release, dependencies are monitored for known vulnerabilities, and reported issues are triaged by severity with a target time to fix.

Diligence

Ask, and we send the documents.

We answer questionnaires directly and send the underlying material — some of it under NDA.

  • Our ISO 27001:2022 certificate
  • Our SOC 2 Type II certificate
  • Encryption design — cipher suites, protocol versions and key management
  • Hosting provider, regions and the residency options open to your fund
  • Backup, retention and recovery objectives, with restore-test evidence
  • Data processing terms, alongside our Privacy Policy
Your data, your control

We hold it. You own it.

The commercial relationship should never be the reason your data is hard to reach. Ownership, export and deletion are treated as ordinary platform functions.

  • Your fund, investor and portfolio data remains yours, including the records CapHive derives from it
  • Export on demand — structured data and the original documents, in formats you can load elsewhere
  • Retention and deletion on your instruction, subject to the records the law requires us to keep
  • Tenant isolation, so one client's data is not queryable from another client's context
  • Permissions granular enough to give an administrator, an analyst and an LP three different views of the same fund
  • AI agent access scoped to the same permissions as the user who invoked it, with every agent action written to the audit trail
Questions

What diligence teams ask us.

What is your position on SOC 2 and ISO 27001?

Our information security management system is certified against ISO/IEC 27001:2022, and we hold a SOC 2 Type II position alongside it. Ask us and we will walk your team through the control set, answer your questionnaire against it, and share the underlying material — the ISO certificate and scope statement, and our SOC 2 documentation under NDA.

Where is our data hosted?

On managed cloud infrastructure, in a region agreed with you at implementation. Indian and US funds frequently have different residency requirements, and the platform is designed to keep those separate rather than assume one default. We will confirm the provider and region in writing during diligence.

Who at CapHive can see our data?

A small number of engineering and support staff, and only where access is needed to operate the platform or resolve a request you have raised. Production access is restricted, requires an approved reason, and is logged.

Client-side visibility is entirely under your control through roles and permissions. We do not need a general-purpose account inside your fund to support you.

Do you support SSO and multi-factor authentication?

Central identity management and multi-factor authentication are part of how we expect institutional teams to use the platform, alongside role-based access. Ask us for the current position on your identity provider and we will answer specifically.

What is your incident response process?

Detect and contain, assess what data and which clients are affected, notify the clients concerned, remediate, then review what allowed it to happen. Affected clients hear from us directly rather than reading a status page.

Can we run a penetration test?

Client-initiated testing is something we are willing to discuss, scoped in writing and run against a non-production environment so live fund data is never in range. We will agree the scope, the window and the reporting route before anything starts.

Disclosure

Report a vulnerability.

If you have found a security issue in CapHive, tell us before you tell anyone else. We will acknowledge the report, keep you updated while we investigate, and credit you if you want the credit.

Security disclosure

Send a description of the issue, the steps to reproduce it and anything you think we should not touch while investigating. Please do not test against live client data.

support@caphive.com

Diligence, reviews and suspected incidents

For questionnaires, data processing terms or a walkthrough with the people who built the controls — or if you believe an account has been compromised and need sessions and credentials revoked — come straight to us.

Contact CapHive or write to hello@CapHive.com

Keep going

The rest of the paperwork.

Our policies set out how personal data is handled and what the contract covers. Read them alongside this page.

See CapHive on your own fund data.

Book a walkthrough with our team — funds, portfolios, deals & secondaries, end to end.

or write to hello@CapHive.com