Security & Compliance
How Prism protects fund data, investor records, documents, approvals, exports, integrations, AI workflows and platform access across managed cloud and private deployment models.
How Prism protects fund data, investor records, documents, approvals, exports, integrations, AI workflows and platform access across managed cloud and private deployment models.
Prism is Perspect’s enterprise investment operations platform for private equity, venture capital, infrastructure, fund-of-funds, family office and investment operations teams. It is designed to manage sensitive operating data including portfolio valuations, investor commitments, capital calls, LP records, KYC materials, documents, reports, approvals, audit logs, integrations and Investor Portal access.
Security in Prism is applied across multiple layers: identity, tenant isolation, role-based access, document controls, auditability, AI governance, integrations, imports, exports, reporting, infrastructure and deployment model. The aim is simple: the right authenticated user should access the right tenant data, for the right purpose, through a controlled and auditable workflow.
Prism can be used as managed Prism Cloud, or discussed as a standalone private deployment for organisations that require local, private cloud or customer-controlled environments.
Security model
Security controls mapped to investment operations risk
Prism is designed around the operating risks investment teams face every day: unauthorised access, weak approval controls, incorrect document visibility, uncontrolled exports, fragmented audit evidence and sensitive data movement.
Identity
JWT-based application sessions, password hashing, tenant context, role context and OIDC SSO support for enterprise identity providers.
Tenant boundary
Fund records, CRM records, reports, documents, settings, branding, AI configuration and audit data are designed to stay scoped to the authenticated tenant.
Documents
Documents are handled through controlled application workflows with authentication, permission checks, portal visibility rules and audit trails where configured.
Governance
Approval workflows, role-based permissions, audit logs, export controls and AI usage controls help keep sensitive operations reviewable.
Authentication and access control
Access is governed by identity, role and tenant context
Prism is designed so permissions are enforced by the application and backend, not merely by hiding buttons in the browser.
Role-based permissions
Administrators can assign roles and permissions so users only access the platform areas and actions appropriate to their responsibilities.
Enterprise SSO
Prism supports OIDC single sign-on for identity providers such as Microsoft Azure AD, Okta and Google Workspace, allowing organisations to align access with corporate identity controls.
MFA through identity policy
Where SSO is configured, organisations can rely on their identity provider’s MFA and conditional access policies. Prism access can therefore sit inside existing enterprise controls.
Tenant isolation
Every customer should operate inside its own controlled tenant boundary
Tenant separation is central to Prism’s security model. The platform is designed so users do not choose their tenant from the browser; tenant context is assigned from authenticated server-side session information.
Tenant-scoped records
Funds, assets, LPs, GPs, contacts, documents, reports, templates, approvals, audit logs, API keys, webhooks, branding settings and AI configuration are designed to remain scoped to the owning organisation.
Portal isolation
Investor Portal users follow a narrower access model. Portal users are intended to see only the LP, fund, document and reporting material made available to them by the fund manager.
Documents and portal security
Documents need controlled access, not public file paths
Prism is designed around authenticated document access, permission checks, portal publication controls and document activity evidence.
Upload validation
Uploaded files should be validated server-side for allowed type, size and workflow context before they become available inside the platform.
Authenticated downloads
Document downloads should be served through application routes that verify the requesting user, tenant, role and document-level permission before returning file content.
Watermarking and access logs
Investor Portal downloads can support recipient-aware watermarking and access logging so fund managers have a clearer record of who accessed which materials and when.
Audit logging and governance
Sensitive platform actions should leave evidence
Investment operations teams need defensible records around user activity, approvals, document access, exports, AI usage and configuration changes.
Record changes
Important fund, CRM, document, reporting, user and settings changes can be captured in audit trails for review and accountability.
Approvals
Approval decisions can record who reviewed the item, when the action occurred and what decision was taken.
Exports
Report, CSV, XLSX, PDF and audit exports should be traceable to the user and tenant that generated them.
AI usage
AI-assisted actions can be logged so administrators can understand how AI features are being used inside the tenant.
AI governance
AI should assist controlled workflows, not bypass them
Prism’s AI features are positioned as assistance for extraction, analysis and drafting. Durable finance records, reports and investor-facing outputs should remain subject to human review and approval where appropriate.
Tenant-level configuration
AI providers, credentials, availability and usage policies are intended to be configured at tenant level, not shared across unrelated organisations.
Usage controls
AI workflows should respect usage limits, budgets, file limits, token limits, concurrency controls and audit logging to reduce cost and data-governance risk.
Human review
AI-generated commentary, extracted fields and analysis should be reviewed by authorised users before being relied on, published or used in formal reporting.
Imports, exports and integrations
Data movement is treated as a controlled workflow
Imports, exports, API ingest, webhooks and BI data exchange can all move sensitive information. Prism is designed to keep those workflows tenant-scoped, permission-aware and auditable.
Imports
Bulk imports should validate data before writing records, helping reduce malformed data, accidental overwrites and wrong-field mapping.
Exports
Exports should respect tenant, role and permission context before producing CSV, XLSX, PDF, BI or audit output.
API keys
API keys are intended to be tenant-scoped and suitable for controlled data ingest, not broad access across unrelated organisations.
Webhooks
Outbound webhook events should be tenant-specific so one organisation’s activity cannot trigger another organisation’s integrations.
Connected security controls
Security connects across the Prism product surface
Security is not limited to login. It needs to apply across reporting, AI, investor access, integrations, CRM, approvals, tenant branding and deployment choices.
Reporting
Report generation, approvals, exports and publication should remain permission-aware and reviewable.
Investor Portal
LP-facing access should remain scoped, read-oriented, document-controlled and tied back to investor records.
AI
AI assistance should stay governed by tenant configuration, usage controls, logging and human review expectations.
Integrations
Imports, API keys, exports, webhooks and BI pathways should be tenant-specific and controlled.
Deployment security
Choose Prism Cloud or discuss customer-controlled deployment
Some organisations want a managed SaaS application. Others need local, private cloud or customer-controlled hosting for procurement, data-control or security reasons.
Managed SaaS security model
Prism Cloud is the Perspect-managed hosted version of Prism. It gives teams a faster route to production while Perspect manages the core application environment, updates and platform operations.
Standalone deployment for stricter environments
For organisations with tighter security, hosting, procurement, data residency or internal control requirements, Perspect can discuss standalone Prism deployment in a customer-controlled environment.
Compliance and privacy
Designed with UK data protection and enterprise review in mind
Prism supports controlled processing of business, investor and operational data. Customers with strict legal, regulatory or procurement needs should review the Privacy Policy, Terms of Service and any agreed data processing documentation.
Privacy documentation
The Privacy Policy explains how Perspect handles personal data across the website, Prism Cloud, demo environment, Investor Portal and related services.
Commercial terms
The Terms of Service explain Prism Cloud subscription terms, private deployment distinction, data export, retention, AI features and customer obligations.
Cookie information
The Cookie Policy explains the cookies and browser storage used across the website, Prism Cloud, demo environment and deployment models.
Perspect takes security reports seriously. If you believe you have discovered a vulnerability in Prism, the Investor Portal, the demo environment or the Perspect website, please report it responsibly before public disclosure.
Email [email protected] with a description of the issue, reproduction steps, affected area, potential impact and any supporting information. Please do not access, modify, destroy, download or disclose data that does not belong to you while investigating a suspected issue.
Perspect will review credible reports and prioritise remediation based on severity, exploitability and customer impact.
Need security, procurement or deployment information?
Contact Perspect for vendor due diligence, security questionnaires, data processing requests, Prism Cloud questions or private deployment discussions.
Security evaluation pages
Deployment and procurement checks