Security

Investor trust starts with data you can trust.

TenX is built so founders can share sensitive company information with confidence, and investors can rely on it.

Encryption everywhere

All data is encrypted in transit with TLS 1.2+ and at rest. Sensitive integration credentials are encrypted with per-field keys.

Isolated workspaces

Every company's data lives in a logically isolated workspace. Updates are shared only with the investors you explicitly choose.

Verified investor identities

Investor accounts must verify their email before any portal data loads, and LP invitations are bound to single-use emailed tokens — nobody can claim an inbox they don't own.

Safe file sharing

Uploads are screened for active content, and shared decks and data rooms only ever render safe formats — never scripts. Every download is served with hardened headers.

Abuse protection

Every state-changing request is CSRF-protected. Sign-in lockouts, per-IP rate limits and origin checks keep brute force and forged requests out.

Auditable actions

Sign-ins, plan changes, document shares and signatures land in an append-only audit trail, so you always know who did what and when.

Compliance

Built toward the standards enterprises expect.

Payments are processed by Stripe, a PCI-DSS Level 1 provider, and TenX never stores raw card data. Role-based access separates founders, investors and admins, and per-investor information rights control exactly what each investor sees. We follow secure development practices with recurring security audits and are building toward SOC 2. Enterprise customers can request our security overview and a review call.