Security

How your documents and figures are protected.

Version 2026-09-01 · Last updated 1 September 2026

Account separation

Every request, document, extracted figure, readiness note and dossier section is tied to the account that created it, and the database refuses to return rows belonging to anyone else. A capital provider sees only the specific dossier shared with them, and only while that share is active.

Documents

Uploaded files live in private storage with no public listing and no public URL. Viewing a file issues a short-lived signed link to your signed-in session only.

In transit and at rest

All traffic uses HTTPS. Stored data and backups are encrypted at rest by our infrastructure provider.

Accounts and passwords

Passwords must be at least 12 characters, are screened against known breached-password lists, and are never stored in readable form. Sign-in attempts and password reset requests are rate limited. Resetting a password ends other active sessions.

Secrets

Service credentials and AI keys are held as server-side secrets. They are never sent to the browser and never appear in a dossier or export.

Reporting a problem

If you believe you have found a vulnerability, write to security@ventureble.com with the details. We will acknowledge within two business days and will not pursue anyone who reports in good faith and does not access other people's data.

Current status

Dossier is in controlled pilot. Malware scanning of uploads, immutable dossier versioning and independent penetration testing are on the roadmap and are not yet in place — please take that into account before uploading highly sensitive records.