Security
Your deals are not ours to share.
Ventura processes confidential pitch decks, financials and cap tables. We built the security model around limiting who can reach them, where they're stored, and what leaves the platform.
Last reviewed · September 2026
TLS
In transit
AES-256
At rest
Private
Document storage
No training
On your data
Security at a glance
Isolation & access
Access is denied by default. Separation happens at the database, not as a rule the application has to remember to apply.
- Database-level isolation
- Access to every business table is denied unless a Postgres row-level security policy grants it. The rule lives in the database, beneath the application, so it applies to every query that reaches it.
- Server-side authorization
- Each API route re-establishes who you are from the session cookie before doing anything. Identity, role and permissions are never taken from the browser's word for it.
- Administrative access
- Admin access is a field on your account record, re-read from the database on every administrative request. Nothing in the browser can set it.
- Private document storage
- The document bucket is not public and has no readable URL. Files are reached only through signed links, generated per request and expiring within the hour.
Encryption & infrastructure
Encrypted in transit and at rest, on infrastructure we don't operate ourselves.
- TLS in transit
- Every connection is encrypted. HTTP is redirected, never served.
- AES-256 at rest
- Applied by our infrastructure providers across database storage, backups and uploaded files alike.
- Point-in-time recovery
- The database can be restored to any moment, not merely to last night's snapshot.
- Managed platforms
- Ventura runs on Vercel and Supabase rather than servers we patch ourselves, behind a global edge network with DDoS mitigation in front of it.
AI & data processing
Ventura calls OpenAI through its API rather than any consumer product. Data submitted over the API is not used to train OpenAI's models — that is OpenAI's standing commitment to API customers — and we train no models of our own on your data either.
Sent to OpenAI
- Relevant document text for the extraction, insight or report you requested
- Your prompt
- Nothing on a schedule or in the background — only when you take an action
Sent to Tavily
- Company and sector names, for market research queries
- Never document contents or financial data
Accounts & sign-in
Authentication doesn't stop at the login screen.
- Two-factor authentication
- Authenticator-app codes are available on every account and required for administrative access. Enforcement covers pages and sensitive API endpoints alike, so it can't be stepped around by calling an endpoint directly.
- Sessions expire and rotate
- Access tokens last one hour. Refresh tokens rotate on every use, so a token captured once can't be replayed indefinitely.
- Sign-in codes are single-use
- Ten-minute validity, one live code per address, and failed attempts are counted — a six-digit code can't be ground down across its lifetime.
- Revoking access ends the session
- When an administrator ends someone's access, the next sign-in is refused and the session already in progress is torn down rather than left behind as a working cookie.
- Accounts are provisioned, not self-served
- An administrator creates the account; the person sets their own password on first use. The provisioning password is never shown, emailed, or logged.
Subprocessors
Who receives information from Ventura — the complete list, not the highlights.
- Supabase
- Database, authentication, file storage — everything you upload, and everything derived from it.
- OpenAI
- Extraction, insights and chat — document contents and prompts, via the API.
- Tavily
- Market and industry research — company and sector names only, never document contents.
- People Data Labs
- Founder and team enrichment — names and public profile identifiers.
- Loops
- Transactional email — name and email address.
- PostHog
- Product analytics — usage events, tied to an account only once you sign in.
- Vercel
- Application hosting and edge delivery — request metadata.
We update this list when we add a provider.
Current security posture
Ventura is an early-stage product used by a small number of firms. Here is what exists, and what doesn't — stated the same way.
Implemented
- Row-level tenant isolation
- Private document storage
- Signed, expiring document URLs
- Server-side authorization
- Multi-factor authentication
- Rotating refresh tokens
- Point-in-time database recovery
- API-based model access
Not yet available
- SOC 2 Type II report
- Independent penetration test
- Customer-facing audit logs
- Dedicated customer infrastructure
Security reporting
Found something?
If you believe you've found a security issue in Ventura, email hello@k2studio.co with “security report” in the subject. We aim to acknowledge within two business days, and we'll tell you what we found and when it was fixed. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it first.
For how we collect and handle personal data, see our privacy policy.