App-owned content

Trust & Security

This page is maintained by vcready.pro to answer common security and privacy questions about the platform. It is not an independent certification or audit report.

Access & Authentication

vcready.pro uses password-based and Google OAuth sign-in. Authenticated sessions are backed by JWT tokens issued by our managed auth provider. Founder and investor accounts are separated, and account creation requires a verified email address.

Data Protection

Data is encrypted in transit over TLS and encrypted at rest by our managed database and storage provider using their platform defaults. Access to founder and investor records is enforced at the database layer through row-level security policies, so each account can only read and write rows it owns. Secrets and API keys are stored as server-side environment variables and are never exposed to the browser.

Platform & Hosting

The application is built and hosted on a managed cloud platform. Database and storage services are provided by the same managed backend. The platform handles infrastructure patching, TLS termination, and baseline DDoS protection. App-level security practices are the responsibility of vcready.pro.

Document Watermarking

Document watermarking (viewer identity stamped onto shared PDFs) is a Test-tier BoardRoom feature and applies only to documents shared from a Test-tier room. Higher tiers and free previews do not currently apply watermarking automatically.

Data Collection & Use

We collect account information (name, email), founder profile data (company name, stage, sector), investor profile data (fund name, focus areas), and engagement analytics (document views, time spent, download events) to provide the BoardRoom service. We do not sell personal data to third parties. Analytics are used only to surface signals to founders about investor intent.

Cookies & Analytics

The platform uses essential cookies for authentication and session management. We do not use third-party advertising cookies. Any analytics are limited to product improvement and are not shared externally.

Retention & Deletion

Account and room data are retained while the account is active. Founders can delete documents and rooms from their BoardRoom at any time. If you wish to delete your entire account and associated data, contact us using the email below and we will process the request within 30 days.

Privacy Requests & Contact

For data access, correction, or deletion requests, or any privacy-related questions, please contact us at privacy@vcready.pro. We will respond within a reasonable timeframe.

Incident & Vulnerability Reporting

If you discover a security issue, please report it responsibly to security@vcready.pro. We will investigate and respond promptly. Please do not publicly disclose vulnerabilities before we have had a chance to address them.