Security

Your deals are not ours to share.

Ventura processes confidential pitch decks, financials and cap tables. We built the security model around limiting who can reach them, where they're stored, and what leaves the platform.

Last reviewed · September 2026

TLS

In transit

AES-256

At rest

Private

Document storage

No training

On your data

—

Security at a glance

01Tenant isolationPostgres row-level security plus server-side authorization.
02Document securityPrivate storage, reached only through expiring signed URLs.
03AuthenticationAuthenticator-app MFA, rotating sessions, single-use sign-in codes.
04AI privacyAPI-based model access only — nothing you upload trains a model.
05InfrastructureVercel and Supabase, encrypted storage, point-in-time recovery.
01

Isolation & access

Access is denied by default. Separation happens at the database, not as a rule the application has to remember to apply.

Database-level isolation
Access to every business table is denied unless a Postgres row-level security policy grants it. The rule lives in the database, beneath the application, so it applies to every query that reaches it.
Server-side authorization
Each API route re-establishes who you are from the session cookie before doing anything. Identity, role and permissions are never taken from the browser's word for it.
Administrative access
Admin access is a field on your account record, re-read from the database on every administrative request. Nothing in the browser can set it.
Private document storage
The document bucket is not public and has no readable URL. Files are reached only through signed links, generated per request and expiring within the hour.
02

Encryption & infrastructure

Encrypted in transit and at rest, on infrastructure we don't operate ourselves.

TLS in transit
Every connection is encrypted. HTTP is redirected, never served.
AES-256 at rest
Applied by our infrastructure providers across database storage, backups and uploaded files alike.
Point-in-time recovery
The database can be restored to any moment, not merely to last night's snapshot.
Managed platforms
Ventura runs on Vercel and Supabase rather than servers we patch ourselves, behind a global edge network with DDoS mitigation in front of it.
03

AI & data processing

Ventura calls OpenAI through its API rather than any consumer product. Data submitted over the API is not used to train OpenAI's models — that is OpenAI's standing commitment to API customers — and we train no models of our own on your data either.

Sent to OpenAI

  • Relevant document text for the extraction, insight or report you requested
  • Your prompt
  • Nothing on a schedule or in the background — only when you take an action

Sent to Tavily

  • Company and sector names, for market research queries
  • Never document contents or financial data
04

Accounts & sign-in

Authentication doesn't stop at the login screen.

Two-factor authentication
Authenticator-app codes are available on every account and required for administrative access. Enforcement covers pages and sensitive API endpoints alike, so it can't be stepped around by calling an endpoint directly.
Sessions expire and rotate
Access tokens last one hour. Refresh tokens rotate on every use, so a token captured once can't be replayed indefinitely.
Sign-in codes are single-use
Ten-minute validity, one live code per address, and failed attempts are counted — a six-digit code can't be ground down across its lifetime.
Revoking access ends the session
When an administrator ends someone's access, the next sign-in is refused and the session already in progress is torn down rather than left behind as a working cookie.
Accounts are provisioned, not self-served
An administrator creates the account; the person sets their own password on first use. The provisioning password is never shown, emailed, or logged.
05

Subprocessors

Who receives information from Ventura — the complete list, not the highlights.

Supabase
Database, authentication, file storage — everything you upload, and everything derived from it.
OpenAI
Extraction, insights and chat — document contents and prompts, via the API.
Tavily
Market and industry research — company and sector names only, never document contents.
People Data Labs
Founder and team enrichment — names and public profile identifiers.
Loops
Transactional email — name and email address.
PostHog
Product analytics — usage events, tied to an account only once you sign in.
Vercel
Application hosting and edge delivery — request metadata.

We update this list when we add a provider.

06

Current security posture

Ventura is an early-stage product used by a small number of firms. Here is what exists, and what doesn't — stated the same way.

Implemented

  • Row-level tenant isolation
  • Private document storage
  • Signed, expiring document URLs
  • Server-side authorization
  • Multi-factor authentication
  • Rotating refresh tokens
  • Point-in-time database recovery
  • API-based model access

Not yet available

  • SOC 2 Type II report
  • Independent penetration test
  • Customer-facing audit logs
  • Dedicated customer infrastructure

Security reporting

Found something?

If you believe you've found a security issue in Ventura, email hello@k2studio.co with “security report” in the subject. We aim to acknowledge within two business days, and we'll tell you what we found and when it was fixed. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it first.

For how we collect and handle personal data, see our privacy policy.