SECURITY & ACCESS

The right people, the right actions, a complete record.

Acquifolio workspaces belong to an organization. Roles decide who can read or change each area, scoped grants decide what outside parties can see, and the server checks both on every request — the interface only reflects them.

Acquifolio v2 is available. This page describes controls in the current product. Role boundaries are checked by automated API tests and by signing in as an owner, viewer, guest and investor. What is not yet available is listed at the end; the roadmap has the full status.

7 + 2internal roles plus guest and investor
35permissions, checked server-side
SHA-256checksum on every file version
15 minaccess tokens, rotating refresh

Internal roles

Every member has one role per organization. A person can belong to several organizations with a different role in each.

Owner

Full control of the firm: settings, members, and every approval (IC, closing, valuations, funds, reports).

Can invite and assign any role

Admin

Manages settings, members and records. Cannot vote at IC or issue approvals.

Can invite and assign any role except Owner and Admin

Partner

Investment lead: works every module and approves IC, closings, valuations and reports. Cannot manage members.

Cannot invite or change members

Deal team

Works deals end to end: financial quality, models, diligence, data room and financing.

Cannot invite or change members

Finance

Runs fund operations, capital events and allocator analytics. Read access to records and portfolio.

Cannot invite or change members

Operator

Manages owned companies, plans and exit readiness. Read access to deals.

Cannot invite or change members

Viewer

Read-only across internal workspaces (no audit log).

Cannot invite or change members

External participants

Guest (advisor / counsel / lender / seller)

External advisor, counsel, lender or seller. Sees only the deals, folders or companies explicitly granted.

Access only through scoped grants

Investor (LP)

LP / co-investor. Investor portal only, limited to their own interests.

Investor portal only, through investor grants

How grants work

A grant gives one person read or write access to one deal, folder, company, fund or investor record, with an optional expiry. Expired grants stop working but stay on record for attribution.

Created by Owners and Admins

Permission matrix

Organization-wide permissions by role, copied from the role map the API enforces (contracts/permissions.ts). A request outside a role’s permissions — and any active grant — is refused, whatever client sends it.

Scroll sideways to see every role.

PermissionOwnerAdminPartnerDeal teamFinanceOperatorViewerGuestInvestor
Organization
Manage organization settings, modules and workflow rulesorg.manageAllowedAllowedNot allowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Invite members, change roles, grant accessmembers.manageAllowedAllowedNot allowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Read the audit logaudit.readAllowedAllowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Read companies, contacts, tasksrecords.readAllowedAllowedAllowedAllowedAllowedAllowedAllowedOnly through a grantNot allowed
Edit companies, contacts, tasksrecords.writeAllowedAllowedAllowedAllowedNot allowedAllowedNot allowedOnly through a grantNot allowed
Deals & diligence
Read dealsdeals.readAllowedAllowedAllowedAllowedNot allowedAllowedAllowedOnly through a grantNot allowed
Create and edit dealsdeals.writeAllowedAllowedAllowedAllowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Override a stage gate (exception)deals.stage_exceptionAllowedAllowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Review earnings evidence (QoE)qoe.reviewAllowedAllowedAllowedAllowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Release an underwriting modelmodels.releaseAllowedAllowedAllowedAllowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Run diligence requests and findingsdiligence.writeAllowedAllowedAllowedAllowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Manage the data roomdataroom.manageAllowedAllowedAllowedAllowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Committee, financing & closing
Vote at investment committeeic.voteAllowedNot allowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Record the IC decisionic.decideAllowedNot allowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Edit financing and lender proposalsfinancing.writeAllowedAllowedAllowedAllowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Confirm a closingclosing.confirmAllowedNot allowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Portfolio & exit
Read portfolio resultsportfolio.readAllowedAllowedAllowedAllowedAllowedAllowedAllowedOnly through a grantNot allowed
Report results, run plansportfolio.writeAllowedAllowedAllowedNot allowedNot allowedAllowedNot allowedOnly through a grantNot allowed
Approve valuationsvaluations.approveAllowedNot allowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Read exit readinessexit.readAllowedAllowedAllowedAllowedNot allowedAllowedAllowedOnly through a grantNot allowed
Prepare exit readiness and offersexit.writeAllowedAllowedAllowedNot allowedNot allowedAllowedNot allowedOnly through a grantNot allowed
Funds & investors
Read funds and capital activityfunds.readAllowedAllowedAllowedNot allowedAllowedNot allowedAllowedOnly through a grantNot allowed
Record capital activity and draftsfunds.writeAllowedAllowedAllowedNot allowedAllowedNot allowedNot allowedOnly through a grantNot allowed
Approve calls, distributions, releasesfunds.approveAllowedNot allowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Read LP Lens analysislplens.readAllowedAllowedAllowedNot allowedAllowedNot allowedAllowedOnly through a grantNot allowed
Edit LP Lens analysislplens.writeAllowedAllowedAllowedNot allowedAllowedNot allowedNot allowedOnly through a grantNot allowed
Investor portalportal.readNot allowedNot allowedNot allowedNot allowedNot allowedNot allowedNot allowedOnly through a grantAllowed
Intelligence, learning & reports
Read docket intelligenceintel.readAllowedAllowedAllowedAllowedNot allowedNot allowedAllowedOnly through a grantNot allowed
Edit watchlists and deadlinesintel.writeAllowedAllowedAllowedAllowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Use Academyacademy.useAllowedAllowedAllowedAllowedAllowedAllowedAllowedOnly through a grantNot allowed
Manage Academy cases and cohortsacademy.manageAllowedAllowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Read reportsreports.readAllowedAllowedAllowedAllowedAllowedAllowedAllowedOnly through a grantNot allowed
Issue reportsreports.issueAllowedNot allowedAllowedNot allowedNot allowedNot allowedNot allowedOnly through a grantNot allowed
Files
Download filesfiles.readAllowedAllowedAllowedAllowedAllowedAllowedAllowedOnly through a grantNot allowed
Upload files and new versionsfiles.uploadAllowedAllowedAllowedAllowedAllowedAllowedNot allowedOnly through a grantNot allowed

“grant” means an external guest has no organization-wide access; they reach only the specific records granted to them. Admins cannot change or remove Owners or other Admins, and an organization always keeps at least one Owner.

Link-based invitations

01

An Owner or Admin invites an email address with a role they may assign — and, for guests and investors, the grants they receive.

02

Acquifolio returns the invitation link once. Only a hash of its token is stored.

03

The inviter shares the link through their own channel — Acquifolio does not send email yet.

04

The recipient sets a password (or confirms an existing account) within seven days. Pending invitations can be revoked.

Controls in the v2 platform

Data isolation per organization

  • Every record carries its organization, and every query is scoped to the organization in the signed session — the client never supplies it.
  • The member’s role is loaded from the membership on every request, not trusted from the token, so role changes and removals apply immediately.
  • Members of several organizations switch explicitly; each switch issues a session for that organization only.
  • Requests for another organization’s records are refused; cross-organization isolation is part of the automated API checks.

External participants

  • Guests (advisors, counsel, lenders, sellers) have no organization-wide permissions; they reach only the deals, data-room folders or companies granted to them, optionally until an expiry date.
  • A guest opening a granted deal sees a minimal deal header, the data-room folders shared with them, their own requests and Q&A, and — for lenders — the released financing package.
  • Pricing, earnings analysis, models, findings, IC memos and votes, closing, activity and comments stay internal; the API redacts or refuses them for guests.
  • Investors (LPs) use the investor portal only, and see only their own released notices, statements, entitled documents and questions. One LP cannot read another LP’s records.

Evidence files & data room

  • Files attach to a specific record — a deal, request, folder or company — up to 25 MB each. Accepted types: PDF, Excel (xlsx, xls), CSV, Word (docx, doc), PowerPoint (pptx), PNG, JPEG, plain text and Markdown.
  • Each file and each new version records a SHA-256 checksum, size, uploader and time. Uploading a new version keeps the prior versions.
  • Every view and download is logged; each file has an access log showing who retrieved which version and when.
  • Data-room folders can be view-only, and the same folder rules apply to every download route.

PDF watermarking

  • In folders marked for watermarking, PDFs are stamped on every page — deal name, viewer name and email, and a UTC timestamp — whenever they are viewed or downloaded through the data room. Participants cannot bypass this through another download route.
  • The stored original is never modified; the checksum shown is always the original’s.
  • The access log records whether the watermark was applied, or why not: non-PDF files, encrypted or unreadable PDFs are sent unaltered and logged as not applied.
  • Viewing is an access policy, not copy protection — files are still transferred to the viewer’s browser.

Audit trail & versioned records

  • Every change that mutates data writes an audit event with the actor, record and summary; each record has an Activity history.
  • Owners, Admins and Partners can read and filter the organization audit log.
  • Versioned records carry a revision number; an edit based on a stale revision is rejected instead of overwriting a colleague’s work.
  • Issued data is corrected by a new linked record, never overwritten, and IC approvals bind to a specific version — a later change marks them stale.

Document text

  • Text is extracted in the background from PDF (per page), Word (docx) and Excel (xlsx, per sheet) uploads, so files can be searched by content and read in a text viewer.
  • Extracted text follows exactly the same access rules as the file itself: external participants reach only the text of files shared with them, and view-only folder rules still apply.
  • The assistant reads document text with the asking user’s permissions and cites the page it quotes.
  • There is no OCR: scanned PDFs and images, and older XLS, DOC and PPTX files, are stored and versioned but not text-searchable.

Single sign-on (OIDC)

  • OpenID Connect per organization, with presets for Google Workspace, Microsoft Entra ID and Okta, plus any generic OIDC provider.
  • Owners and Admins configure connections and allowed email domains, and choose just-in-time provisioning (the default role is never Owner or Admin) or invitation-only access. SSO can be enforced for those domains.
  • Owners keep an audited break-glass password login.
  • Tokens never appear in URLs and each sign-in is bound to the browser that started it. Consumer domains such as gmail.com are refused, one domain maps to one organization, and in production issuer endpoints that resolve to private network addresses are refused.
  • Domains rely on admin attestation; there is no DNS-based domain verification.

Multi-factor authentication

  • Authenticator-app codes (TOTP, RFC 6238) with 10 single-use recovery codes, replay protection and lockout after repeated failures.
  • Organizations can require MFA for everyone or for selected roles; members who must enrol can reach only MFA setup until they do.
  • For SSO sign-ins, an organization can choose to trust the identity provider’s MFA.
  • MFA secrets are encrypted at rest with AES-256-GCM, and an admin MFA reset is audited.

Sessions & credentials

  • Passwords are at least 12 characters and stored as bcrypt hashes.
  • Access tokens last 15 minutes; refresh tokens rotate on use, are stored only as hashes, and reuse of an old token revokes the whole session family.
  • “Sign out everywhere” invalidates every access and refresh token for the account at once.
  • Removed members are rejected on their next request, even with an unexpired token.

Assistant and workflow rules

Assistance drafts and organizes internal work; authorized people decide. Neither acts on its own outside the workspace.

AI assistant

  • Answers questions with read-only tools that run with the asking user’s own permissions — it cannot see anything the user cannot.
  • Every figure cites its source record, with its definition and period; citations that match no source are flagged as unsupported, and unknown figures are reported as unavailable.
  • It cannot create, change or approve anything. IC memo drafts are proposals a person reviews, inserts and saves.
  • Each question is audited with metadata only (records, tools, citation counts, outcome) — not the question or answer text.
  • Disabled, with the reason shown, when no AI provider API key is configured. Investors never get the assistant; guests get only grant-aware tools on what they were granted.

Workflow rules

  • Rules only create internal work: tasks, diligence requests, internal comments and review flags.
  • They never send email or messages and never change prices, terms, approvals or capital records.
  • Owners and Admins create rules; a rule must be previewed against current records before it can be activated, and edits return it to draft as a new version.
  • Each effect has a deterministic key, so a repeated event never creates duplicate work, and every run is recorded and audited.

Not yet available

Plan any use with external participants or regulated data around these boundaries; the product says so where they apply.

SAML and SCIM

Single sign-on uses OpenID Connect only. There is no SAML, no SCIM provisioning or deprovisioning, no IdP-initiated login and no single logout.

Passkeys, SMS and email codes

MFA uses authenticator-app codes. Passkeys / WebAuthn, SMS or email codes and “remember this device” are not available.

Email delivery

Invitation links are copied and shared by the inviter. Notices, digests and assignments are not emailed, and there is no email-based password reset; screens that would need email say so.

S3 / object storage

Files are stored on the API server’s disk behind a storage abstraction; managed object storage is planned.

Malware scanning

Uploads are checked for type and size, not scanned for malicious content.

OCR

Scanned PDFs and images are not read; text is extracted only from PDF, docx and xlsx files that contain text.

Independent certification

Acquifolio holds no SOC 2, ISO 27001 or similar certification, and does not claim one.

Questions from your security reviewer?

The trust page explains how financial evidence and review decisions stay distinct; the roadmap shows what is available and what is planned.

Create a workspace