Security with clear controls and honest limits.

PitchSeen keeps sensitive logic and credentials on the server, stores opportunity documents privately, and requires founder-approved, document-specific access before an investor can open protected files.

Updated 23 September 2026 · Security information, not a certification

Private by defaultUploaded documents are not public links.
Document-scoped approvalThe founder chooses the exact files an investor may receive.
Recorded access stepsVerification and acknowledgement events are time-stamped.

Server-side architecture

Provider credentials, private storage controls, support configuration, and sensitive business logic remain on PitchSeen servers. The browser or mobile client receives only what is needed for the signed-in session. Connections use HTTPS, passwords are stored as strong hashes, and privileged actions are restricted by role.

Document handling

Uploads are checked for permitted type and size, scanned for malware, and kept in private storage. The pitch deck, executive summary, delivery timeline, and financial report are separate protected documents. Founders can approve, pause, revoke, or expire access; replacing a file creates a new document version rather than silently changing the evidence record.

Investor access sequence

  • The investor requests one or more documents.
  • The founder is notified and approves or rejects each requested document.
  • Approved requests for the same investor and opportunity may be combined into one secure invitation.
  • PitchSeen verifies the investor's registered mobile number with a one-time code.
  • The investor accepts the displayed confidentiality, restricted-use, and non-circumvention acknowledgement before the approved files open.

A link alone does not grant access. Adding another document later requires a fresh approval and acknowledgement for the expanded document set.

Evidence records

PitchSeen records the acknowledgement version and hash, acceptance time, opportunity, approved document set and versions, and security/session references. These records support an audit trail of platform events. They are not a legal opinion, a guarantee of identity or authority, or a promise about admissibility or litigation outcome.

Identity and entity checks

Individual investors may be asked for a government-issued identity document. Family offices, venture funds, corporate investors, and other entity accounts may also be asked for commercial registration or an equivalent entity document. PitchSeen does not request proof of personal wealth or investment capacity. Verification does not amount to endorsement or due diligence.

Operational protection

Controls include role-based access, administrative audit trails, rate limits, short-lived sessions and links, least-privilege service access, backups, account-export and deletion workflows, and restricted support access. SMS verification is delivered through Twilio; transactional email is delivered through SendGrid.

Limits and responsible reporting

No application can fully prevent screenshots, photography, copying, compromised devices, or reverse engineering. PitchSeen reduces exposure without claiming absolute prevention. Do not put secrets or algorithms in a client application. Report a suspected vulnerability or unauthorised access to hello@pitchseen.com; include enough detail to reproduce it and do not access other users' data.