SECURITY PROCUREMENT

Security procurement checklist for private capital software

Private capital software holds investor, portfolio, deal and document information. Procurement should test how the platform protects data, controls access, records changes and supports vendor due diligence before sensitive workflows move into production.

Access control

Review internal roles, external portal permissions, tenant isolation and least-privilege controls.

Audit evidence

Check whether changes, approvals, document publication and user actions leave usable records.

Data handling

Understand hosting, backups, exports, retention, support access and incident-response expectations.

Security questions to ask vendors

  • Can permissions vary by fund, investor and contact?
    Investor portal and document controls need more than broad user roles.
  • Can audit logs explain what happened?
    Logs should help reconstruct changes, approvals and publication events.
  • How is production access controlled?
    Ask who can access customer data, under what circumstances and with what oversight.
  • How are exports and offboarding handled?
    Buyers should understand how data can be exported if they leave.

Evaluate Prism directly

Use the live Prism demo and public pricing to decide whether the platform fits before starting a formal buying process.

Building an RFP?

Use the private capital software RFP checklist to compare workflow, governance, reporting, migration and implementation requirements.

Evaluation checklist

Use the investor portal RFP checklist to compare requirements, rollout risk, controls and operational readiness.