invested.io
Home About Team FAQ Contact
Login
Home About Team FAQ Contact Login

Trust Center

Security & Trust at invested.io

How we protect your data, and where responsibilities sit.

Your company’s data is sensitive, and it is yours. invested.io is built so that Operators can see their own business clearly and share only what they approve with their investors in a secure environment. Similarly, investors can see relevant information about their investments, but that information is not shared with any other third parties. This page explains the security measures we have in place, the certifications we hold or that are in progress, how our integrations work, and the division of responsibilities between you, invested.io, and the providers that support our platform.

Our security posture

invested.io runs on enterprise-grade cloud infrastructure and follows recognized security frameworks. Our current standing:

CASA Tier 2 certified invested.io has been granted Cloud Application Security Assessment (CASA) Tier 2 certification, an independent review of our application security practices.
SOC 2 in progress We are actively engaged in a SOC 2 Type 2 examination with an independent auditor. We will update this page when the report is available.
Encryption Data is encrypted in transit using TLS and at rest using AES-256.
Access controls Access to systems and data is restricted by role, protected by multi-factor authentication, and reviewed on a regular cadence.
Monitoring Our production environment is continuously logged and monitored, with alerting for unusual activity.

How our integrations work

invested.io connects to the tools Operators already use to calculate over 100 standardized business metrics across cash, revenue, customers, sales, profitability, balance sheet, fundraising, team, and compliance. Two principles govern every connection:

Read-only access

Every integration is read-only. invested.io cannot make changes inside Operators’ connected systems. Neither can investors. Operators remain the only party with full access to, and the ability to edit, your source data. Similarly, investors can read but not edit information shared with them by Operators.

Query, don’t collect

We do not bulk-copy your underlying records. invested.io queries the systems Operators connect, pulls only the specific data points needed to calculate metrics, and leaves the source data where it belongs. We store discrete metrics only — the calculated data points themselves — not copies of your source records.

Operators can disconnect any integration at any time, and can request full deletion of their company’s data from our system. Investors can likewise request full deletion of their data from our system.

What we connect to

Depending on the Operator’s company, you may connect some or all of the following categories. Connecting more sources produces a more complete metric picture, but every connection is optional and under your control:

  • Banking and cash data, through our vendor Plaid
  • Accounting software (QuickBooks Online, Xero, FreshBooks)
  • Billing software (Stripe)
  • Payroll and HRIS platforms (Gusto)
  • CRM systems (HubSpot, Salesforce, Pipedrive, Attio)
  • Spreadsheets and workspaces (Google Sheets, Notion)
  • Document folders for contracts and agreements, through read-only access to a folder you designate (Google Drive, Dropbox)
  • Cap table tools (Ledgy), or a cap table you upload directly
  • CSV uploads for data not covered by a direct integration

Operators drive the sharing of information with investors

Connecting Operators’ systems to invested.io does not give investors access to your accounts or your raw data. Investors never log into your tools, and they never see your underlying records; investors can see derivative information calculated from your data sources, such as those concerning revenue, profitability and headcount, once you approve those integrations and metrics.

The providers that support our platform

invested.io relies on a small set of established providers to operate the platform. Each is bound by contract to protect your data and to use it only to provide services to us. Our key providers include:

  • Cloud infrastructure and hosting — our production environment runs on Amazon Web Services (AWS).
  • Banking connectivity — bank and cash data is accessed through Plaid’s secure API.
  • Payment processing — subscription billing is handled by Stripe. We do not store full card numbers.
  • AI and machine learning — we use established AI providers (including Anthropic and OpenAI) to generate insights. These providers are contractually prohibited from using your data to train their general-purpose models.

This list may grow over time, and we will periodically update this document to reflect those changes.

We do not use your data to train general-purpose AI models, and we do not sell your personal information. For the full list of how data is shared, see our Privacy Policy.

Shared responsibility

Security is a partnership. The table below gives a high-level view of how responsibilities are divided between you, invested.io, and the providers that support our platform. We will publish a more detailed version once our SOC 2 examination is complete.

Your responsibility invested.io’s responsibility Our providers’ responsibility
Manage your own account credentials and enable multi-factor authentication. Authenticate users, enforce access controls, and protect the platform. Secure the underlying cloud infrastructure and physical data centers.
Decide which systems to connect and which investors may view your data. Query only the data needed for metrics; keep integrations read-only. Maintain the security and availability of their own connected services.
Provide accurate data and review reports before sharing them. Compute metrics, encrypt data in transit and at rest, and monitor for threats. Process data only as instructed by invested.io and under contract.
Disconnect integrations or request deletion when you choose. Honor disconnection and deletion requests and retain data per policy. Notify invested.io of relevant security or availability events.

Reporting a security concern

If you believe you have found a security vulnerability or have a question about our security practices, please contact us at privacy [at] invested.io or legal [at] invested.io. We take all reports seriously and will respond promptly.

For privacy questions or to exercise your data rights, contact privacy [at] invested.io. For other inquiries, contact legal [at] invested.io.

Related documents

  • Terms and Conditions
  • Privacy Policy

This page is maintained by invested.io and will be updated as our security program evolves, including upon completion of our SOC 2 examination. Last updated: June 2, 2026.

invested.io

The metrics and analytics platform for operators and investors building great companies.

Company

  • About
  • Team
  • Contact

Resources

  • FAQ
  • Getting Ready
  • Trust Center
  • Terms of Service
  • Privacy Policy
© 2026 invested.io. All rights reserved.
Built for operators and investors.

Get in early

invested.io is currently invite-only. Enter your invite code, or join the waitlist.

Pre-launch members get free access for a while after launch.

You’re on the list.

We’ll reach out as invites open up.

Getting ready? See what you’ll need to get set up