Security

Controls built for sensitive fundraising work

Roundly combines verified identity, company-scoped authorization, encrypted provider credentials, review-gated actions, and audit records. This page describes controls present in the product; it does not claim an external certification.

Last updated August 31, 2026

Identity and session protection

  • Passwordless and social identity is handled through WorkOS AuthKit when configured.
  • Roundly accepts only verified email identities and rejects provider impersonation sessions.
  • Production sessions use secure, HTTP-only, host-only cookies, bounded return paths, and same-origin sign-out.
  • One active WorkOS session is enforced per user, with device visibility and revocation controls.

Company and data isolation

  • Server-side authorization checks the company and role for protected reads and writes.
  • Ambiguous multi-company identities fail closed instead of silently selecting a workspace.
  • OAuth credentials and protected wire instructions are encrypted at rest using server-held keys.
  • Document, email, funding, and cap-table changes create source-aware audit records.

Human control

Roundly can monitor and prepare work, but it does not treat an outbound statement as proof of investor action. Email, protected documents, wire instructions, funding status, cap-table adjustments, and AI-recommended writes remain reviewable and role-restricted.

Report a security concern

Please send a concise description, affected URL or account, reproduction steps, and impact to support@getroundly.ai. Do not include live access tokens, passwords, bank account numbers, or unredacted investor documents in the first message.