Data Permissions
Your data, your rules — at every level
Team-level privacy boundaries, IP-based access restrictions, and enterprise-grade controls that scale across teams and offices without slowing down deal velocity.


.webp)
Secure data management built for private capital
Team-based access controls
Protect sensitive deal and relationship intelligence.
Secure data sharing
Share data with portfolio companies, co-investors, and LPs through permission-based controls with complete audit trails.
Enterprise security
End-to-end encryption, SOC2, ISO27001, and a comprehensive privacy framework built in.
Control information access with precision
Define custom permission sets for different teams and roles, ensuring sensitive data is only accessible to authorized personnel while adhering to SOC2, ISO27001, and a comprehensive privacy framework.


Manage external collaboration safely
Share specific lists and relationship data with portfolio companies, co-investors, and LPs through permission-based access controls that maintain complete audit trails and data privacy compliance. IP Allowlists add another layer—restrict platform and API access to approved networks so you always know exactly who's reaching your data.


Implement comprehensive data protection
End-to-end encryption, isolated AWS Virtual Private Cloud deployment, multi-factor authentication, and daily encrypted backups—certified by SOC2, SOC3, and ISO27001/27017/27018/27701 standards.

Where to next?
Enterprise-grade security
SOC2, ISO27001, and comprehensive security frameworks to safeguard sensitive relationship data.
Trust center
Detailed info about our security certifications and enterprise compliance standards.
Privacy policy
How we protect your data privacy and maintain granular controls over sensitive information.
SOC 3 report
Independently audited security, availability, and confidentiality standards.
Frequently Asked Questions
Deal-level permissions restrict access to a specific deal and its associated relationship data, rather than granting access by job title across everything. A professional can be a full CRM user and still see nothing of a transaction they are not staffed on. Role-based access alone cannot express that, which is why information barriers built on roles tend to leak.
Granular access control at the deal and fund level, scoped external sharing instead of exports, complete audit trails, network restrictions such as IP allowlists, encryption in transit and at rest, multi-factor authentication, and independent certification. An institutional LP running operational diligence will ask for SOC 2 Type II and ISO 27001 by name.
Affinity admins define custom permission sets by team and role, applied at the user, deal, and fund level. External collaborators such as portfolio companies, co-investors, and LPs get scoped access through permission-based sharing instead of exported files, and every access is recorded in a complete audit trail.
Affinity is certified against SOC 2, SOC 3, and ISO 27001, 27017, 27018, and 27701. The platform runs in an isolated AWS Virtual Private Cloud deployment with end-to-end encryption, multi-factor authentication, and daily encrypted backups. IP allowlists restrict platform and API access to approved networks.
Yes. Custom permission sets and team-based access controls create privacy boundaries between teams inside a single instance, so a private equity team and a private credit team work on shared relationship data while each team's deals and diligence stay restricted. The boundaries scale across teams and offices without a services engagement.
No. Admins configure permission sets themselves and change them as teams and mandates shift. This matters more than it sounds since information barriers that need a vendor ticket to update tend to lag the org chart, which is the state in which they fail.









