Data Permissions

Your data, your rules — at every level

Team-level privacy boundaries, IP-based access restrictions, and enterprise-grade controls that scale across teams and offices without slowing down deal velocity.

Data access comparison table for Enterprise Admin, Admin, and Standard rolesAccount Role filter dropdown with Enterprise Admin and Admin selected

Secure data management built for private capital

Custom

Team-based access controls

Protect sensitive deal and relationship intelligence.

Custom

Secure data sharing

Share data with portfolio companies, co-investors, and LPs through permission-based controls with complete audit trails.

ISO certification icon
Custom

Enterprise security

End-to-end encryption, SOC2, ISO27001, and a comprehensive privacy framework built in.

Control information access with precision

Define custom permission sets for different teams and roles, ensuring sensitive data is only accessible to authorized personnel while adhering to SOC2, ISO27001, and a comprehensive privacy framework.

Users and permissions settings with account role assignments for each user

Manage external collaboration safely

Share specific lists and relationship data with portfolio companies, co-investors, and LPs through permission-based access controls that maintain complete audit trails and data privacy compliance. IP Allowlists add another layer—restrict platform and API access to approved networks so you always know exactly who's reaching your data.

Collaborators settings page listing external users with status, saved views, and type

Implement comprehensive data protection

End-to-end encryption, isolated AWS Virtual Private Cloud deployment, multi-factor authentication, and daily encrypted backups—certified by SOC2, SOC3, and ISO27001/27017/27018/27701 standards.

Security compliance badges: AICPA SOC 2, GDPR, DPF, ISO 27001, ISO 27017, and ISO 27018

What customers are saying

"Implementation was really easy. We were able to start using the platform straight away."
Udai Chopra
Principal
Read case study
"Having a well-defined, clean, golden source data set is more important in the age of AI. That's a lot of the benefit we're seeing from Affinity."
Oren Michaely
Head of AI
Read case study
"It's night and day. We are way
more organized when it comes
to relationships. We've won a
good amount of deals we wouldn't have won if we hadn't changed over to Affinity."
Doug Parker
Head of Origination
Read case study
"Venture capital is a craft, and Affinity is one of the tools helping the investment team build this craft better."
Moustafa ElBialy
CIO
Read case study

Where to next?

ISO certification icon
Custom

Enterprise-grade security

SOC2, ISO27001, and comprehensive security frameworks to safeguard sensitive relationship data.

Custom

Trust center

Detailed info about our security certifications and enterprise compliance standards.

decorative
Custom

Privacy policy

How we protect your data privacy and maintain granular controls over sensitive information.

Custom

SOC 3 report

Independently audited security, availability, and confidentiality standards.

Frequently Asked Questions

Deal-level permissions restrict access to a specific deal and its associated relationship data, rather than granting access by job title across everything. A professional can be a full CRM user and still see nothing of a transaction they are not staffed on. Role-based access alone cannot express that, which is why information barriers built on roles tend to leak.

Granular access control at the deal and fund level, scoped external sharing instead of exports, complete audit trails, network restrictions such as IP allowlists, encryption in transit and at rest, multi-factor authentication, and independent certification. An institutional LP running operational diligence will ask for SOC 2 Type II and ISO 27001 by name.

Affinity admins define custom permission sets by team and role, applied at the user, deal, and fund level. External collaborators such as portfolio companies, co-investors, and LPs get scoped access through permission-based sharing instead of exported files, and every access is recorded in a complete audit trail.

Affinity is certified against SOC 2, SOC 3, and ISO 27001, 27017, 27018, and 27701. The platform runs in an isolated AWS Virtual Private Cloud deployment with end-to-end encryption, multi-factor authentication, and daily encrypted backups. IP allowlists restrict platform and API access to approved networks.

Yes. Custom permission sets and team-based access controls create privacy boundaries between teams inside a single instance, so a private equity team and a private credit team work on shared relationship data while each team's deals and diligence stay restricted. The boundaries scale across teams and offices without a services engagement.

No. Admins configure permission sets themselves and change them as teams and mandates shift. This matters more than it sounds since information barriers that need a vendor ticket to update tend to lag the org chart, which is the state in which they fail.

decorative