Back to StartupCFO

Security

Security at StartupCFO

Last updated: July 14, 2026

Our approach

StartupCFO handles sensitive company and financial information. Our security approach is to limit access, separate organization data, rely on established infrastructure providers, and give founders direct control over what leaves their workspace. Security is an ongoing practice, not a one-time certification or guarantee.

Authentication and access control

Authentication is provided through Clerk. StartupCFO uses authenticated sessions, organization-scoped access, and role-based permissions to separate founder workspaces. Organization administrators are responsible for reviewing team membership, assigning appropriate roles, and removing access when it is no longer needed.

Connected financial services

Bank connections are provided through Plaid and payment or revenue connections may be provided through Stripe. StartupCFO uses the access authorized for the feature you select. We do not ask users to send bank passwords through StartupCFO. Third-party connections remain subject to the security and availability of the relevant provider.

Application and data safeguards

Our safeguards are designed around practices that include:

  • Organization-level authorization checks for financial data.
  • Limited administrative access based on operational need.
  • Dependency, configuration, and change review during development.
  • Logging and investigation of important application activity.
  • Backups and recovery capabilities provided by our infrastructure.
  • Use of service providers selected for the function they perform, including authentication, database, payments, financial connections, email, and AI processing.

No system is immune from failure or attack. We do not claim a security certification unless it is expressly identified as current and applicable.

Investor Portal controls

Investor Portals are separate from the founder operating workspace. Founders choose what is staged for investor review and may use open, email-gated, invitation, expiration, revocation, and approval controls. Deeper diligence materials can remain behind founder approval. Founders should treat any active share link as sensitive and review it before sending.

AI and service providers

When an AI-assisted feature is used, StartupCFO may send the minimum relevant context to an AI service provider to perform the requested operation. We do not intentionally use founder financial data for advertising. Our Privacy Policy describes the categories of providers used to operate the service.

Your responsibilities

Use a secure account, protect your devices and credentials, review organization membership, and revoke access promptly when roles change. Do not upload information you are not authorized to process. Review financial outputs and Investor Portal contents before relying on or sharing them. Contact us immediately if you suspect unauthorized access.

Incident response

We investigate credible reports of unauthorized access, data exposure, and service abuse. If we determine that an incident affects users, we will provide notice and information consistent with applicable law and the facts available to us.

Report a vulnerability

Send suspected security issues to support@gostartupcfo.com. Include the affected URL or feature, steps to reproduce, and your contact information. Do not access, alter, retain, or disclose data that does not belong to you, and do not disrupt the service while testing.