Security

Secure bymandate.

Institution-grade security, privacy, and control — built for the most confidential work in finance.

Data protection, by design

Siloed storage

Your firm’s data is stored in a fully siloed environment — isolated from every other Pitchcrow customer and dedicated to you.

Encrypted end to end

AES-256 encryption at rest and TLS 1.2+ in transit — the same standard the institutions we serve run on.

Deployed to your infrastructure

If your policies require it. Flexible deployment options with no shared resources, down to running inside your own environment.

Never trained on your data

First rule of Pitchcrow: your documents, prompts, and decks never train our models, or anyone else’s.

As per your protocols

Authentication, access, and audit controls that fit inside your firm’s compliance perimeter — not the other way around.

Authentication and users

Comprehensive SSO support — SAML or OIDC — with multi-factor authentication and just-in-time provisioning, IdP- or SP-initiated.

Permissions and document security

Restrict permissions down to individual decks, spaces, folders and files. Members see only what they have been explicitly granted, and nothing else.

Audit logging

Opening, editing, commenting on and deleting decks; deleting items from a deck; uploading, viewing and downloading space files; uploading to and viewing the template library; opening chat sessions; and every permission grant and revocation — each entry carrying user, timestamp, IP address and device.

Privacy, prized

The controls behind the product — the people, machines, and policies that handle your firm’s data.

Employees, thoroughly vetted

Every employee passes a background check and signs a confidentiality agreement. Company machines are managed by MDM, with full-disk encryption and anti-malware enforced.

Your data stays yours

Nothing you upload trains a model, and nothing lingers — your firm’s data can be exported or permanently deleted on request.

SOC 2 Type II
Underway with Vanta
ISO 27001
Planned 2026

Frequently asked questions

The questions we answer in every diligence review — and the answers, up front.

Everything your firm brings to or creates on the platform: uploaded documents, space files, prompts, chat history, decks, and their metadata. All of it is handled at the same confidentiality tier.

No. Your documents, prompts, and decks are never used to train Pitchcrow’s models — or any third party’s.

Only the people your admins grant. Permissions can be restricted down to individual decks, spaces, folders and files, and every access is recorded in the audit log.

On AWS, encrypted at rest with AES-256 and in transit with TLS 1.2+. Each firm’s data sits in its own fully siloed environment.

Yes — for firms whose policies require it, we offer dedicated deployments with no shared resources, up to and including your own infrastructure. Talk to us about what your protocols demand.

Opening, editing, commenting on and deleting decks; deleting items from a deck; uploading, viewing and downloading space files; uploading to and viewing the template library; opening chat sessions; and every permission grant and revocation — each entry carrying user, timestamp, IP address and device.

Experience the new eraof investment banking

Schedule a Demo