Security built around firm isolation and control.
Cap Orbit keeps each firm separate, keeps each deal inside its own workspace, and treats customer files, prompts, and outputs as private work product, not training data. Pro gives teams that foundation in a managed deployment. Enterprise puts the same platform inside your AWS account, behind your identity, network, and key controls.
At a glance
The controls that matter before a deal file goes in.
Start with isolation, access control, model handling, and Enterprise deployment. The full control catalog is in the trust center.
Isolation
Each firm gets its own environment
Every organization runs on its own database, document storage, and execution roles. Customer data is not pooled across firms.
Access
Access is narrow and temporary
A request reaches customer data during an active signed-in session, scoped to the right firm and the work being performed.
Identity
Sign-in follows your directory
On Enterprise, Cap Orbit uses your identity provider for single sign-on, so access follows your directory and offboarding path.
Privacy
No model training on your work
Deal files, prompts, outputs, templates, and work product are used to run your deals. They are not used to train models.
Deployment
Your cloud boundary on Enterprise
Enterprise deploys into an AWS account your firm owns, in the region you choose, with customer-held encryption keys.
Control
Audit with your own tools
On Enterprise, resources and logs live in your account, so your security team can monitor activity and revoke access directly.
Pro and Enterprise
Start managed, or deploy inside your own boundary.
Both tiers run the same product security foundation. The difference is where the platform lives and who controls the surrounding infrastructure.
Pro
A secure managed deployment
For funds and investment teams up to fifty people. Cap Orbit manages the infrastructure while your firm runs on dedicated resources with isolated deal workspaces, access controls, encryption, and no training on customer data.
Enterprise
In the account your firm owns
The same platform deployed into your own AWS account, in your region. Single sign-on, private connectivity, customer-held encryption keys, and AI provider choices are configured against your security and architecture review.
Firm isolation
Firm and deal boundaries are built into the architecture.
Each organization has its own data stores and permissions. Inside the firm, each deal has its own workspace, files, and context.
Database
A dedicated database per organization
Each firm gets its own database. Service permissions are scoped to that database, and broad default database access is revoked.
Storage
Dedicated document storage
Files, drafts, and work product sit in storage tied to that firm’s environment. One firm’s materials are not visible to another.
Permissions
Dedicated execution permissions
Each organization has its own execution roles, so services working for one firm do not have permissions into another firm’s environment.
Per deal
Each deal in its own workspace
Inside a firm, each deal runs with its own files, drafts, sessions, and context, keeping work product clean across transactions.
Enforcement
Boundaries enforced below the app
The application does not rely on naming conventions to keep firms apart. Database grants and storage roles enforce the boundary underneath it.
Mapping
No shared customer store
A firm resolves to its own data store and document location. The mapping is constrained so two firms cannot point at the same customer store.
Access model
Access stays tied to the user, the firm, and the work.
Cap Orbit does not leave standing access open to customer data. Requests are checked against the active session, scoped to one firm, and expire automatically.
- 01
01
Start with a signed-in user
A request starts from a live user session. On Enterprise, that session is governed by your identity provider.
- 02
02
Scope access to one firm
The request is matched to the firm it belongs to before any customer data is reached.
- 03
03
Reject mismatches before data is touched
If the requested firm, user, or data store does not line up, the request stops before reaching customer data.
- 04
04
Expire access automatically
Temporary access expires after the request window, so access does not remain open after the work is done.
Your files, prompts, and outputs are not training data.
Cap Orbit reads your deal materials to produce the model, memo, analysis, and record your team asked for. That work stays in your environment and is not used to train models.
Deal files
Rent rolls, T-12s, leases, appraisals, and term sheets are read to do the deal work and remain in your environment.
Prompts and instructions
The directions your team gives are part of your deal record, not material for training or cross-customer reuse.
Models, memos, and work product
The output belongs to your firm, stays with the deal, and remains exportable as your work product.
Audit and control
On Enterprise, oversight sits in your account.
Enterprise deployment lets your security team monitor the platform with the logging, identity, and cloud controls it already operates.
Your logs
Logs in your environment
Resources and logs sit in your cloud account, where your team can review them with its existing monitoring stack.
Revocation
Access can be cut off directly
Because the deployment is in your account, your team can revoke access through your own identity, network, and key controls.
Architecture
Review the deployment before rollout
Enterprise is configured against your security and architecture review, including identity, networking, encryption, region, and inference path.
Security review
Answers your security team can verify.
What counts as our data, and where does it live?
Your deal files, prompts, team activity, models, memos, exports, and work product. On Pro it lives on dedicated resources for your firm. On Enterprise it lives inside a cloud account you own, in the region you choose. It is not pooled with another firm’s data.
Who can access our data, and how?
Access starts with a live, signed-in user from your organization. Requests are scoped to that firm, checked before they reach customer data, and expire automatically. On Enterprise, sign-in runs through your identity provider, so access follows your directory and offboarding path.
Can we deploy Cap Orbit in our own cloud account?
Yes, on Enterprise. The same platform deploys into a cloud account your firm owns, with private connectivity, customer-held encryption keys, and the region and AI provider choices agreed during security and architecture review.
How is one firm’s data kept separate from another’s?
Each organization gets its own database, document storage, and execution roles. Inside the firm, each deal has its own workspace. The boundary is enforced by database grants and storage permissions underneath the application.
Can we audit access and revoke it ourselves?
Yes, on Enterprise. Resources and logs sit in your account, so your team can monitor the deployment with your existing tooling and revoke access through your own identity, network, and key controls.