Security

Your cap table is only seen by the people you name.

The short answer

Capable encrypts your cap table in transit and at rest, stores it in the United States, requires only the access each person’s role allows, logs every change and export, and holds AI-proposed changes for an admin’s approval. You can export everything at any time.

  • Passwordless sign-in with enforceable two-factor
  • Private US file storage with no public URLs
  • 30-day point-in-time database recovery
  • Breach notification within 72 hours

Encrypted in transit and at rest

  • Every connection uses TLS 1.2 or higher, with HTTP Strict Transport Security.
  • The database is encrypted at rest on Turso. Uploaded files are encrypted at rest in a private S3-compatible bucket on Railway; files uploaded before that move remain in private Vercel storage.
  • Files have no public URLs. Every download goes through an authorized application route.

Two-factor you can require

  • Passwordless sign-in by email link or Google, so there is no reusable password to steal.
  • TOTP two-factor authentication for any user.
  • A company owner can require two-factor for everyone in the company.

Roles that match how companies work

  • Owner, Admin, HR admin, Billing admin and Read only, set per company.
  • Every database query is scoped to a company the user belongs to.
  • Stakeholders see only their own holdings, documents and tasks, never anyone else's.

AI access is scoped and needs approval

  • The Claude and ChatGPT connector uses OAuth 2.1 with PKCE, short-lived access tokens, and tokens you can revoke.
  • Tokens carry your role and reach only companies you already belong to.
  • Write tools create proposals. Nothing on the cap table changes until an authorized admin approves.

Everything is written down

  • The audit log records every transaction, correction, export and document download, with the actor and time.
  • Corrections keep history instead of overwriting it.
  • You can answer who took a copy of the cap table, and when.

Signatures that hold up

  • Each signer's consent to sign electronically is recorded with IP address, browser details and timestamps, as ESIGN and UETA expect.
  • Executed documents carry a hash of the signed content.
  • What was signed is frozen at sending, so a later template edit cannot change it.

We run the service with the same controls we promise in the DPA

Backups and recovery
The database is backed up continuously, with point-in-time restore for 30 days. The service runs on managed cloud infrastructure with provider-level redundancy.
Change management
Every deployment comes from a reviewed commit that passes type checking and the automated test suite. Database schema changes are applied deliberately, never by a live request.
Access by our team
Production access is limited to the engineers who operate the service, with single sign-on and multi-factor authentication. We access customer data only to provide support you request, to investigate security or abuse, or where the law requires.
AI model providers
AI requests send only the data needed for that request, through Vercel AI Gateway, and model providers may not train on it.
Incident response
We notify affected customers of a personal data breach without undue delay and within 72 hours, by email to company owners and admins.
Your data after you leave
Cancel from inside the app. Without an active plan the cap table is read-only, and exports stay open. Deletion after termination follows the schedule in our DPA.

The binding version of these measures is Annex 2 of our Data Processing Addendum.

Your data is processed by 10 named subprocessors, all listed here

This list is the same one published at /legal/subprocessors and in the DPA.

Capable subprocessors
SubprocessorPurposeLocation
VercelVercel Inc.Application hosting, content delivery, legacy file storage, and the AI Gateway that routes AI requests to model providersUnited States
TursoChiselStrike, Inc.Primary databaseUnited States (AWS us-west-2)
RailwayRailway CorporationPrivate S3-compatible file storage and Redis cacheUnited States
StripeStripe, Inc.Subscription billing and payment processingUnited States
ResendPlus Five Five, Inc.Transactional email deliveryUnited States
OpenAIOpenAI, LLCAI model provider for the in-app assistant, import mapping, and connector features, reached through Vercel AI GatewayUnited States
AnthropicAnthropic, PBCAI model provider for the in-app assistant, import mapping, and connector features, reached through Vercel AI GatewayUnited States
GoogleGoogle LLCSign in with GoogleUnited States
FinchFinch · optionalHRIS and payroll connectivity, only for companies that connect an HR systemUnited States
CloudflareCloudflare, Inc.DNS for capable.soGlobal network

Found a vulnerability? Tell us and we reply within one business day

Email security@capable.so with the affected feature, the impact and steps to reproduce.

Our responsible disclosure policy sets out what is in scope, the rules for good-faith research, and our safe harbor commitment.

Capable runs no marketplace, brokerage or fund, so nobody here has a reason to look at your cap table except to help you.

Security questions, answered

Is Capable SOC 2 certified?+

Not yet. The controls on this page are in place today, and they are also written into the technical and organizational measures of our Data Processing Addendum. An independent SOC 2 audit is what turns our description into a third party's opinion, and we will say so here when it is complete.

Where is my data stored?+

In the United States. The database runs on Turso in AWS us-west-2, files are in a private S3-compatible bucket on Railway, and the application is hosted on Vercel. The full list of subprocessors and locations is on this page and at /legal/subprocessors.

Who can see my cap table?+

The people you invite, at the role you give them, and stakeholders viewing only their own holdings. Capable runs no marketplace, brokerage or fund, and does not sell your data.

Can the AI connector change my cap table?+

Not on its own. Read tools answer questions. Write tools create a proposal that an authorized admin must approve in Capable before anything changes, and both the proposal and the approval are logged.

How do I report a vulnerability?+

Email security@capable.so. We reply within one business day, and our responsible disclosure policy at /legal/security explains scope and safe harbor for good-faith research.

Do you sign a DPA?+

Yes. Our Data Processing Addendum at /legal/dpa applies to every customer and includes the security measures and subprocessor terms.

Move your equity somewhere it is looked after.

14-day free trial with everything unlocked. Invite counsel as a read-only admin, and export everything whenever you want.