Build Sep 29, 2026, 12:09 PM ET · version da23c6c

Sprowtt — Growing Business in America

Security, Privacy & Platform Controls

Security, privacy, and controls for sensitive deal-room work

How Sprowtt approaches access management, data protection, platform controls and issuer-controlled workspace activity. Sprowtt provides software tools and does not provide legal, tax, accounting, or investment advice.

Our commitment, in plain language

Sprowtt is designed to support secure, organized workspaces for sensitive company materials and stakeholder communications. We focus on clear access controls, responsible data handling and transparent platform practices — and on describing only controls that are actually in place.

Nothing is ever deleted

Nothing is ever deleted. Records are only archived, kept in folders.

Each company has an archive folder holding its full history: offerings, documents, investor records, communications, acceptances, access logs and billing. A record that is withdrawn, cancelled or entered by mistake is archived there with who changed it and when, and can be restored. The database itself refuses a delete. This is for regulatory and legal record-keeping, because an offering's history may need to be produced years later.

Access and permissions

  • Role-based access: company, counsel, investor and administrator roles, checked on the server for every account function — an automated check in the build fails if a function is added without one
  • Workspace-level and document-level visibility, set by the company
  • Invitations for authorized stakeholders, and revocation that takes effect straight away
  • Administrator seats locked to a city or a law firm by the profile, never by the web address
  • Suspending a user signs them out of every session at once
  • Sign-in, sign-up and password-reset attempts are rate-limited
  • Every document open and download is recorded against the version seen
Two-factor sign-in with an authenticator app and backup codes is available on every account, and in production administrator screens stay closed until the administrator has it on. Available controls may vary by plan, configuration and enabled features.

Data protection

Further detail about the hosting environment and the available controls can be provided to qualified customers on request.

  • Encrypted connections (HTTPS) in production, with strict transport security and security headers on every page
  • Uploaded files are never served directly; every read passes an access check
  • An uploaded file must match its declared type by its contents before it is stored
  • Bank routing and account numbers are stored encrypted, and only the last four digits are ever shown
  • Only the last four digits of a taxpayer number are kept on a cap table
  • Database backups, and nothing is ever deleted: a payment or document entered by mistake is voided or archived, so the history survives

Where the platform runs

The platform runs on a virtual private server with its own dedicated CPU, memory and storage, separated from other customers' sites, and with its own dedicated IP address.

The server sits in a U.S. data center facility whose operator holds SOC 2 Type II and ISO 27001 certification and is PCI DSS compliant. Those certifications belong to the data center facility and its operator, not to Sprowtt's own software, and they are not a certification of Sprowtt.

  • Physical security at the facility: security staff on site around the clock, electronic access control with biometric or multi-factor checks, and camera coverage
  • Backup power from UPS systems and on-site generators, and redundant cooling
  • Multiple network carriers with redundant routing
  • Always-on DDoS protection on the hosting network

In the software itself

  • Two-factor sign-in with an authenticator app on every account, required for administrators in production
  • Sign-in, sign-up and password-reset attempts rate-limited
  • Every upload checked so its contents match its declared type, and text files carrying web-page code refused
  • Security headers on every page, including strict transport security and limits on which sites may frame a page
  • Uploaded files served only through an access check, never from a public address
  • Cross-site request checks on every server function, so another website cannot act for a signed-in user
  • Nothing is ever deleted: the database refuses a delete on record tables, and a mistake is archived with who changed it and when
  • An audit trail of who did what and when, exported with each company's archive folder

Privacy and data use

Sprowtt uses personal and workspace information to operate, secure, support and improve the platform, as described in our Privacy Policy. We use contact details submitted through this website to respond to the request made.

In a deal room the software records each document open and download, and the company sees the counts for its own room. Requests to see or correct personal information can be sent to info@sprowtt.com. A correction is recorded alongside the original, so the history stays complete.

Third-party services

Some capabilities rely on third-party providers when they are enabled: hosting and infrastructure, email, video meetings and recording, accreditation verification, payments for subscriptions, and analytics. When enabled, those providers process information under their own contractual terms and privacy practices, and the services available depend on the customer's configuration and agreements.

Where a provider verifies identity or accreditation, processes a payment, or holds escrow, that provider — not Sprowtt — performs the service.

Compliance workflow support

Sprowtt provides configurable software features that may support company and advisor workflows, including document organization, controlled sharing, activity records, counsel review and communications. Sprowtt does not determine whether an offering, disclosure, communication or transaction complies with applicable law.

Companies and their professional advisors remain responsible for their offering, disclosures, communications, eligibility determinations, registrations, exemptions and compliance obligations.

What we are not claiming

Sprowtt itself does not claim a SOC 2 report, an ISO certificate, a PCI attestation, an uptime guarantee or any audit it has not had. The certifications described under Where the platform runs are the data center operator's, for its facility, not Sprowtt's.

Report a concern or request information

To report a security concern, or to request available security documentation as a qualified customer or prospect, email info@sprowtt.com with "Security" in the subject line. For account help, use the same address.

Sprowtt provides technology tools. Nothing on this website or in the platform is legal, financial, tax, accounting, investment, securities or offering advice. Sprowtt does not offer securities, act as a broker-dealer, or operate a funding portal through this website.