CapHive holds capital accounts, investor identity documents and unpublished valuations. This page sets out how that data is protected, who can reach it, and what your fund controls.
Security on a fund platform is not one feature. It is a set of controls that have to hold together — encryption, identity, logging, infrastructure, recovery and the way software gets built.
Data is encrypted in transit between you and the platform, and encrypted at rest in storage and backups. Encryption keys are managed separately from the data they protect.
Role-based access control decides what each user can see and do, down to the fund and the record type. Multi-factor authentication is supported, and access is reviewed when roles change.
Actions that change a record are logged with the user, the time and the before-and-after value — in the interface and through the API. When an auditor asks how a number was produced, the answer is a query rather than a reconstruction.
The platform runs on managed cloud infrastructure, with environments separated and administrative access restricted to a small, named group. Production access requires an approved reason.
Data is backed up on a schedule, backups are encrypted, and restores are tested rather than assumed. Recovery objectives are documented and shared with clients who ask.
Changes are peer reviewed before release, dependencies are monitored for known vulnerabilities, and reported issues are triaged by severity with a target time to fix.
We answer questionnaires directly and send the underlying material — some of it under NDA.
The commercial relationship should never be the reason your data is hard to reach. Ownership, export and deletion are treated as ordinary platform functions.
Our information security management system is certified against ISO/IEC 27001:2022, and we hold a SOC 2 Type II position alongside it. Ask us and we will walk your team through the control set, answer your questionnaire against it, and share the underlying material — the ISO certificate and scope statement, and our SOC 2 documentation under NDA.
On managed cloud infrastructure, in a region agreed with you at implementation. Indian and US funds frequently have different residency requirements, and the platform is designed to keep those separate rather than assume one default. We will confirm the provider and region in writing during diligence.
A small number of engineering and support staff, and only where access is needed to operate the platform or resolve a request you have raised. Production access is restricted, requires an approved reason, and is logged.
Client-side visibility is entirely under your control through roles and permissions. We do not need a general-purpose account inside your fund to support you.
Central identity management and multi-factor authentication are part of how we expect institutional teams to use the platform, alongside role-based access. Ask us for the current position on your identity provider and we will answer specifically.
Detect and contain, assess what data and which clients are affected, notify the clients concerned, remediate, then review what allowed it to happen. Affected clients hear from us directly rather than reading a status page.
Client-initiated testing is something we are willing to discuss, scoped in writing and run against a non-production environment so live fund data is never in range. We will agree the scope, the window and the reporting route before anything starts.
If you have found a security issue in CapHive, tell us before you tell anyone else. We will acknowledge the report, keep you updated while we investigate, and credit you if you want the credit.
Send a description of the issue, the steps to reproduce it and anything you think we should not touch while investigating. Please do not test against live client data.
For questionnaires, data processing terms or a walkthrough with the people who built the controls — or if you believe an account has been compromised and need sessions and credentials revoked — come straight to us.
Contact CapHive or write to hello@CapHive.com
Our policies set out how personal data is handled and what the contract covers. Read them alongside this page.
Book a walkthrough with our team — funds, portfolios, deals & secondaries, end to end.
or write to hello@CapHive.com