Data handling
Data governance
Where your data lives, who can reach it, and what founders control.
What CorvaneOS stores
| Data | Examples | Who can see it |
|---|---|---|
| Workspace content | Projects, tasks, documents, chat | Members of that organization. |
| Business data | Sales, feedback, customers, hiring, cap table | Members of that organization. |
| Investor records | Deals, portfolio, funds, LPs | Members of that investor workspace, by role. |
| Shared startup pages | Sections a founder chose | Investors the founder allowed, or anyone signed in if public. |
Tenant separation
Every record carries the organization or investor workspace it belongs to. Server routes check your membership on every request and never trust an id sent from the browser. Database tables are locked with row-level security so the browser can't read them directly.
Builders and investors
Investor accounts can't open Builder pages. Investors see a startup only through its read-only startup page, limited to the sections and access level the founders chose. See Sharing with investors.
Your customers' data
Feedback and usage data you send through the API is stored for your organization only. Send pseudonymous customer ids where you can, and avoid putting secrets or sensitive personal data in feedback text or metadata.
Demo data
Sample datasets are flagged as demo and removed without touching real records.