Security with clear controls and honest limits.
PitchSeen keeps sensitive logic and credentials on the server, stores opportunity documents privately, and requires founder-approved, document-specific access before an investor can open protected files.
Server-side architecture
Provider credentials, private storage controls, support configuration, and sensitive business logic remain on PitchSeen servers. The browser or mobile client receives only what is needed for the signed-in session. Connections use HTTPS, passwords are stored as strong hashes, and privileged actions are restricted by role.
Document handling
Uploads are checked for permitted type and size, scanned for malware, and kept in private storage. The pitch deck, executive summary, delivery timeline, and financial report are separate protected documents. Founders can approve, pause, revoke, or expire access; replacing a file creates a new document version rather than silently changing the evidence record.
Investor access sequence
- The investor requests one or more documents.
- The founder is notified and approves or rejects each requested document.
- Approved requests for the same investor and opportunity may be combined into one secure invitation.
- PitchSeen verifies the investor's registered mobile number with a one-time code.
- The investor accepts the displayed confidentiality, restricted-use, and non-circumvention acknowledgement before the approved files open.
A link alone does not grant access. Adding another document later requires a fresh approval and acknowledgement for the expanded document set.
Evidence records
PitchSeen records the acknowledgement version and hash, acceptance time, opportunity, approved document set and versions, and security/session references. These records support an audit trail of platform events. They are not a legal opinion, a guarantee of identity or authority, or a promise about admissibility or litigation outcome.
Identity and entity checks
Individual investors may be asked for a government-issued identity document. Family offices, venture funds, corporate investors, and other entity accounts may also be asked for commercial registration or an equivalent entity document. PitchSeen does not request proof of personal wealth or investment capacity. Verification does not amount to endorsement or due diligence.
Operational protection
Controls include role-based access, administrative audit trails, rate limits, short-lived sessions and links, least-privilege service access, backups, account-export and deletion workflows, and restricted support access. SMS verification is delivered through Twilio; transactional email is delivered through SendGrid.
Limits and responsible reporting
No application can fully prevent screenshots, photography, copying, compromised devices, or reverse engineering. PitchSeen reduces exposure without claiming absolute prevention. Do not put secrets or algorithms in a client application. Report a suspected vulnerability or unauthorised access to hello@pitchseen.com; include enough detail to reproduce it and do not access other users' data.