Trust Centre

A single place to review Prism’s security posture, privacy approach, access model, onboarding path, and due diligence contact points

When investment firms evaluate software, they are not only reviewing features. They are reviewing the control model around the product: how data is protected, how tenant isolation works, how access is governed, how investor-facing access is scoped, how implementation is handled, and where legal and security information can be reviewed without chasing multiple documents.

This Trust Centre is designed to make that process simpler. It provides a clear starting point for security and procurement review, while linking out to the deeper pages that explain Prism’s controls, policies, and implementation approach in more detail.

It is not intended to replace the full Security & Compliance page, Privacy Policy, Terms of Service, or onboarding documentation. It is the hub that ties them together.

Trust at a Glance

Encryption in Transit and at Rest

Prism is designed so all browser and API traffic is protected over HTTPS using TLS, with traffic handled through Cloudflare and Nginx. At rest, platform data, uploaded documents, and backups are stored on LUKS-encrypted block storage. Sensitive application-layer secrets are also encrypted before database storage, and passwords are stored only as bcrypt hashes with per-user salts.

Multi-Tenant Isolation

Prism operates as a multi-tenant platform with tenant isolation enforced at the data layer. Data access is scoped using a company identifier bound to the authenticated user, and tenant checks are applied on every request that accesses records, documents, logs, users, or configuration.

Role-Based Access and SSO

Access is governed through role-based controls, with different permissions for administrators, managers, viewers, and portal users. Enterprise tenants can configure OIDC-based SSO with providers such as Azure AD, Okta, and Google Workspace, and can enforce SSO as the exclusive login method for their tenant where required.

Auditability

Prism maintains a tamper-evident audit log covering significant platform actions, including record changes, configuration changes, document access events, and report-related activity. Audit entries are designed to be reviewable by tenant administrators and retained in line with the platform’s retention model.

Security Architecture

Prism’s detailed security position is covered on the Security & Compliance page. This includes data encryption, tenant isolation, role-based access, SSO, audit logging, infrastructure protections, document controls, AI feature controls, and compliance context. Buyers who want the technical detail should start there.

Privacy and Data Handling

For personal data handling, lawful bases, retention, international transfers, and user rights, the Privacy Policy is the authoritative reference. The Trust Centre is intended to point buyers to that detail quickly, not replace it with a shorter summary that omits important legal context.

Terms, Usage, and Commercial Controls

The Terms of Service set out the legal framework for using Prism, including platform use restrictions, subscription terms, data retention and deletion windows, sanctions restrictions, and other contractual rules that buyers and legal teams typically review during diligence.

Implementation and Onboarding

Trust is not just about technical controls. Buyers also want to know what rollout looks like in practice. The Implementation & Onboarding page explains how Prism is introduced through a focused first use case, structured data migration, identity configuration, access setup, and practical first-phase rollout.

Vendor Diligence and Security Review

For security questionnaires, data processing agreement queries, or vendor due diligence review, buyers should use the contact route listed on this page. The intention is to make it easier for procurement and security reviewers to get to the right material without unnecessary back-and-forth.

Infrastructure and Access Summary

Network and Edge Protection

Prism traffic is routed through Cloudflare before it reaches the application layer, providing edge protection and filtering before requests hit the server. Application traffic is then handled through an Nginx reverse proxy rather than exposing the application process directly to the public internet.

Application Availability and Backups

The application runs under managed process supervision, with automated restart and persistence across server restarts. Backups are performed on a daily schedule and retained in encrypted storage to support platform recovery and continuity.

Restricted Administrative Access

Administrative access to platform infrastructure is limited and controlled. Internal services are not exposed directly to the public internet, and operational access is intended to follow tighter administrative controls than a default public-server posture.

Document, Portal, and Investor Controls

Authenticated Document Access

Documents are not intended to be accessible through public URLs or guessable download paths. Access to files is handled through authenticated server-side delivery, with checks against tenant, role, and where relevant LP-linked access rights.

Portal Access Scoped to the Linked LP

Investor Portal access is read-only by design and intended to be scoped only to the fund and document information explicitly made available to the linked LP record. Portal users do not have access to the broader management interface or to other investors’ data.

Document Access Visibility

Document access within the investor-facing experience is designed to be logged so fund managers can review when material was accessed and by whom. This supports a stronger chain of custody around investor-facing document delivery than simple file sharing.

AI and Third-Party Data Processing

AI Features Are User-Initiated

Prism’s AI-supported features are intended to be opt-in and initiated by explicit user action, rather than running as background processing against customer data. This keeps the control point with the user or tenant administrator.

Tenant-Scoped AI Configuration

AI provider configuration is stored per tenant so one tenant’s settings and credentials are not shared with another. This is consistent with the platform’s wider tenant isolation model.

Processing Agreements and Policy Detail

Where third-party AI services or other subprocessors are involved, the detailed legal and data-handling position should be reviewed in the Privacy Policy and related contractual material. The Trust Centre is the entry point, not the substitute for those documents.

Compliance, Review, and Vendor Diligence

Privacy and Regulatory Context

Prism’s trust position is built around UK GDPR-aware data handling, contractual controls around international transfers, and a more structured operating model for records, reporting, and access. Full legal and privacy detail remains in the Privacy Policy and related legal documents.

AML, KYC, and Platform Scope

Prism can support the storage and management of investor identity and KYC-related documentation as part of a fund manager’s workflow, but the platform is not intended to present itself as the regulated party performing AML screening in place of the fund manager.

Security Questionnaires and Data Processing Enquiries

For enterprise security review, DPA discussion, or vendor diligence requests, the simplest route is to contact Perspect directly so the right supporting material can be shared in context.

Security and diligence enquiries
For enterprise security questionnaires, vendor due diligence requests, data processing agreement enquiries, or other trust-related questions, please use the contact route on perspect.finance or email [email protected].

Responsible vulnerability disclosure
If you believe you have identified a security issue affecting Prism or perspect.finance, please report it responsibly before any public disclosure. Include a description of the issue, reproduction steps, and supporting detail where possible.

Registered office / correspondence
Perspect Services Ltd
441 Sidcup Road
London
SE9 4ET
United Kingdom

Security procurement checklist

Questions for access control, audit logs, portal permissions and data handling.

Read more

Self-hosted deployment

Private deployment architecture, PostgreSQL, uploads, TLS and backups.

Read more

Migration from legacy systems

How to migrate active records without recreating legacy complexity.

Read more