Trust Centre
A single place to review Prism’s security posture, privacy approach, access model, onboarding path, and due diligence contact points
A single place to review Prism’s security posture, privacy approach, access model, onboarding path, and due diligence contact points
When investment firms evaluate software, they are not only reviewing features. They are reviewing the control model around the product: how data is protected, how tenant isolation works, how access is governed, how investor-facing access is scoped, how implementation is handled, and where legal and security information can be reviewed without chasing multiple documents.
This Trust Centre is designed to make that process simpler. It provides a clear starting point for security and procurement review, while linking out to the deeper pages that explain Prism’s controls, policies, and implementation approach in more detail.
It is not intended to replace the full Security & Compliance page, Privacy Policy, Terms of Service, or onboarding documentation. It is the hub that ties them together.
Prism is designed so all browser and API traffic is protected over HTTPS using TLS, with traffic handled through Cloudflare and Nginx. At rest, platform data, uploaded documents, and backups are stored on LUKS-encrypted block storage. Sensitive application-layer secrets are also encrypted before database storage, and passwords are stored only as bcrypt hashes with per-user salts.
Prism operates as a multi-tenant platform with tenant isolation enforced at the data layer. Data access is scoped using a company identifier bound to the authenticated user, and tenant checks are applied on every request that accesses records, documents, logs, users, or configuration.
Access is governed through role-based controls, with different permissions for administrators, managers, viewers, and portal users. Enterprise tenants can configure OIDC-based SSO with providers such as Azure AD, Okta, and Google Workspace, and can enforce SSO as the exclusive login method for their tenant where required.
Prism maintains a tamper-evident audit log covering significant platform actions, including record changes, configuration changes, document access events, and report-related activity. Audit entries are designed to be reviewable by tenant administrators and retained in line with the platform’s retention model.
Review Areas
The main trust questions most buyers and procurement teams want answered quickly
Prism’s detailed security position is covered on the Security & Compliance page. This includes data encryption, tenant isolation, role-based access, SSO, audit logging, infrastructure protections, document controls, AI feature controls, and compliance context. Buyers who want the technical detail should start there.
For personal data handling, lawful bases, retention, international transfers, and user rights, the Privacy Policy is the authoritative reference. The Trust Centre is intended to point buyers to that detail quickly, not replace it with a shorter summary that omits important legal context.
The Terms of Service set out the legal framework for using Prism, including platform use restrictions, subscription terms, data retention and deletion windows, sanctions restrictions, and other contractual rules that buyers and legal teams typically review during diligence.
Trust is not just about technical controls. Buyers also want to know what rollout looks like in practice. The Implementation & Onboarding page explains how Prism is introduced through a focused first use case, structured data migration, identity configuration, access setup, and practical first-phase rollout.
For security questionnaires, data processing agreement queries, or vendor due diligence review, buyers should use the contact route listed on this page. The intention is to make it easier for procurement and security reviewers to get to the right material without unnecessary back-and-forth.
Prism traffic is routed through Cloudflare before it reaches the application layer, providing edge protection and filtering before requests hit the server. Application traffic is then handled through an Nginx reverse proxy rather than exposing the application process directly to the public internet.
The application runs under managed process supervision, with automated restart and persistence across server restarts. Backups are performed on a daily schedule and retained in encrypted storage to support platform recovery and continuity.
Administrative access to platform infrastructure is limited and controlled. Internal services are not exposed directly to the public internet, and operational access is intended to follow tighter administrative controls than a default public-server posture.
Documents are not intended to be accessible through public URLs or guessable download paths. Access to files is handled through authenticated server-side delivery, with checks against tenant, role, and where relevant LP-linked access rights.
Investor Portal access is read-only by design and intended to be scoped only to the fund and document information explicitly made available to the linked LP record. Portal users do not have access to the broader management interface or to other investors’ data.
Document access within the investor-facing experience is designed to be logged so fund managers can review when material was accessed and by whom. This supports a stronger chain of custody around investor-facing document delivery than simple file sharing.
Prism’s AI-supported features are intended to be opt-in and initiated by explicit user action, rather than running as background processing against customer data. This keeps the control point with the user or tenant administrator.
AI provider configuration is stored per tenant so one tenant’s settings and credentials are not shared with another. This is consistent with the platform’s wider tenant isolation model.
Where third-party AI services or other subprocessors are involved, the detailed legal and data-handling position should be reviewed in the Privacy Policy and related contractual material. The Trust Centre is the entry point, not the substitute for those documents.
Prism’s trust position is built around UK GDPR-aware data handling, contractual controls around international transfers, and a more structured operating model for records, reporting, and access. Full legal and privacy detail remains in the Privacy Policy and related legal documents.
Prism can support the storage and management of investor identity and KYC-related documentation as part of a fund manager’s workflow, but the platform is not intended to present itself as the regulated party performing AML screening in place of the fund manager.
For enterprise security review, DPA discussion, or vendor diligence requests, the simplest route is to contact Perspect directly so the right supporting material can be shared in context.
Contact and Reporting
Where buyers, security teams, and researchers should direct questions or responsible disclosures
Security and diligence enquiries
For enterprise security questionnaires, vendor due diligence requests, data processing agreement enquiries, or other trust-related questions, please use the contact route on perspect.finance or email [email protected].
Responsible vulnerability disclosure
If you believe you have identified a security issue affecting Prism or perspect.finance, please report it responsibly before any public disclosure. Include a description of the issue, reproduction steps, and supporting detail where possible.
Registered office / correspondence
Perspect Services Ltd
441 Sidcup Road
London
SE9 4ET
United Kingdom
Start with the Trust Centre, then go as deep as your review process needs
Review the detailed security and legal pages, explore implementation expectations, or contact Perspect if you need security review, vendor diligence, or onboarding discussion.
BUYER RESOURCES
Procurement and deployment resources
Questions for access control, audit logs, portal permissions and data handling.
Private deployment architecture, PostgreSQL, uploads, TLS and backups.
How to migrate active records without recreating legacy complexity.