Security with clear controls and honest limits.

PitchSeen keeps sensitive logic and credentials on the server, stores opportunity documents privately, and requires founder-approved, document-specific access before an investor can open protected files.

Updated 23 September 2026 · Security information, not a certification

Private by defaultUploaded documents are not public links.
Document-scoped approvalThe founder chooses the exact files an investor may receive.
Recorded access stepsVerification and acknowledgement events are time-stamped.

Server-side architecture

Provider credentials, private storage controls, support configuration, and sensitive business logic remain on PitchSeen servers. The browser or mobile client receives only what is needed for the signed-in session. Connections use HTTPS, passwords are stored as strong hashes, and privileged actions are restricted by role.

Document handling

Uploads are checked for permitted type and size, scanned for malware, and kept in private storage. The pitch deck, executive summary, delivery timeline, and financial report are separate protected documents. Founders can approve, pause, revoke, or expire access; replacing a file creates a new document version rather than silently changing the evidence record.

Investor access sequence

  • The investor requests one or more documents.
  • The founder is notified and approves or rejects each requested document.
  • Approved requests for the same investor and opportunity may be combined into one secure invitation.
  • PitchSeen verifies the investor's registered mobile number with a one-time code.
  • The investor accepts the displayed confidentiality, restricted-use, and non-circumvention acknowledgement before the approved files open.

A link alone does not grant access. Adding another document later requires a fresh approval and acknowledgement for the expanded document set.

Evidence records

PitchSeen records the acknowledgement version and hash, acceptance time, opportunity, approved document set and versions, and security/session references. These records support an audit trail of platform events. They are not a legal opinion, a guarantee of identity or authority, or a promise about admissibility or litigation outcome.

Identity and entity checks

Individual investors may be asked for a government-issued identity document. Family offices, venture funds, corporate investors, and other entity accounts may also be asked for commercial registration or an equivalent entity document. PitchSeen does not request proof of personal wealth or investment capacity. Verification does not amount to endorsement or due diligence.

Operational protection

Controls include role-based access, administrative audit trails, rate limits, short-lived sessions and links, least-privilege service access, backups, account-export and deletion workflows, and restricted support access. SMS verification is delivered through Twilio; transactional email is delivered through SendGrid.

Limits and responsible reporting

No application can fully prevent screenshots, photography, copying, compromised devices, or reverse engineering. PitchSeen reduces exposure without claiming absolute prevention. Do not put secrets or algorithms in a client application. Report a suspected vulnerability or unauthorised access to hello@pitchseen.com; include enough detail to reproduce it and do not access other users' data.

أمن بضوابط واضحة وحدود صريحة.

تُبقي PitchSeen منطق الأعمال الحساس ومفاتيح الخدمات على الخادم، وتحفظ مستندات الفرص بصورة خاصة، ولا تفتح الملفات المحمية إلا بعد موافقة المؤسس على المستندات المحددة وإتمام المستثمر خطوات التحقق.

آخر تحديث: 23 سبتمبر 2026 · معلومات أمنية وليست شهادة اعتماد

الخصوصية هي الوضع الافتراضيالمستندات المرفوعة ليست روابط عامة.
موافقة لكل مستنديحدد المؤسس الملفات التي يجوز لكل مستثمر فتحها.
خطوات وصول موثقةتُسجل أحداث التحقق والإقرار مع وقتها.

بنية تعتمد على الخادم

تبقى مفاتيح مزودي الخدمة وضوابط التخزين الخاص وإعدادات الدعم ومنطق الأعمال الحساس على خوادم PitchSeen. لا يستلم المتصفح أو تطبيق الهاتف إلا ما تحتاجه الجلسة المسجلة. تستخدم الاتصالات HTTPS، وتُحفظ كلمات المرور كمجزّآت قوية، وتُقيّد العمليات الحساسة بحسب الصلاحيات.

حماية المستندات

يُتحقق من نوع الملف وحجمه وتُفحص الملفات من البرمجيات الضارة ثم تُحفظ في تخزين خاص. يُعامل العرض التقديمي والملخص التنفيذي والجدول الزمني للتنفيذ والتقرير المالي كمستندات مستقلة. يستطيع المؤسس الموافقة على الوصول أو إيقافه أو سحبه أو تحديد انتهائه، ويؤدي استبدال الملف إلى إنشاء نسخة جديدة بدلاً من تغيير سجل الإثبات بصمت.

تسلسل وصول المستثمر

  • يطلب المستثمر مستنداً واحداً أو أكثر.
  • يُخطر المؤسس ويوافق على كل مستند مطلوب أو يرفضه.
  • يمكن جمع الطلبات الموافق عليها للمستثمر نفسه والفرصة نفسها في دعوة آمنة واحدة.
  • تتحقق PitchSeen من رقم الهاتف المسجل للمستثمر باستخدام رمز لمرة واحدة.
  • يوافق المستثمر على إقرار السرية وتقييد الاستخدام وعدم الالتفاف المعروض قبل فتح الملفات الموافق عليها.

الرابط وحده لا يمنح الوصول. وإضافة مستند لاحقاً تتطلب موافقة وإقراراً جديدين يشملان مجموعة المستندات الموسعة.

سجل الإثبات

تسجل PitchSeen إصدار الإقرار وتجزئته ووقت القبول والفرصة ومجموعة المستندات ونسخها ومراجع الأمن والجلسة. يدعم ذلك مسار تدقيق لأحداث المنصة، لكنه ليس رأياً قانونياً ولا ضماناً للهوية أو الصفة ولا وعداً بالقبول القضائي أو نتيجة النزاع.

التحقق من الهوية والكيان

قد يُطلب من المستثمر الفرد تقديم وثيقة هوية حكومية. وقد يُطلب أيضاً من المكتب العائلي أو صندوق رأس المال الجريء أو المستثمر المؤسسي أو حساب الكيان تقديم سجل تجاري أو وثيقة كيان معادلة. لا تطلب PitchSeen إثبات الثروة الشخصية أو القدرة الاستثمارية. ولا يُعد التحقق تزكية أو عناية واجبة.

ضوابط التشغيل

تشمل الضوابط الصلاحيات حسب الدور وسجلات تدقيق الإدارة وتحديد المعدل والجلسات والروابط قصيرة العمر وأقل قدر من الصلاحيات والنسخ الاحتياطي وتصدير الحساب وحذفه وتقييد وصول الدعم. تُرسل رموز التحقق عبر Twilio والبريد التشغيلي عبر SendGrid.

الحدود والإبلاغ المسؤول

لا يستطيع أي تطبيق منع لقطات الشاشة أو التصوير أو النسخ أو الأجهزة المخترقة أو الهندسة العكسية بصورة كاملة. تقلل PitchSeen التعرض دون ادعاء المنع المطلق. لا ينبغي وضع الأسرار أو الخوارزميات الحساسة داخل تطبيق العميل. للإبلاغ عن ثغرة محتملة أو وصول غير مصرح به، راسل hello@pitchseen.com مع تفاصيل كافية للتكرار، ودون الوصول إلى بيانات مستخدمين آخرين.