Security and
confidentiality.
You're uploading documents that are often pre-funding, often confidential, sometimes containing material non-public information. Here's what we do — and don't do — with them.
- Your private workspace history.
Account-owned decks and reports remain in your workspace. Unclaimed uploads expire after 24 hours. File access is checked against your verified account or an authorised staff role.
- Your uploads are never used for training.
Neither our models nor our third-party providers (OpenAI, Anthropic, LlamaIndex) use your decks to train models. Inference only. We have data processing agreements in place that enforce this.
- Encrypted in transit and at rest.
Public services use HTTPS. Workspace data and uploads use Convex in Ireland; analysis runs and results use our processing server. Stripe handles card details.
- Strict access controls.
Row-level security policies in our database ensure you can only access your own analyses, and teammates can only access shared team quotas. No employees access your decks except for triaging a reported issue, with your consent.
- No introductions, no syndication, no brokerage.
We don't connect founders to investors, syndicate deals, or share decks with anyone. The report stays between you and us.
Found a vulnerability? We're grateful. Email assistant@earlycapitalgroup.com with details. We respond within twenty-four hours and credit researchers on our security page (with permission).
Questions we haven't answered? Get in touch.