getstartupfunding logo
  • For Founders
  • For Investors
  • Portfolio
  • Blog
  • Funding, support, and expertise to help early-stage startups succeed

Security

Last updated: June 12, 2026

Get Startup Funding takes the security of the information founders and investors share with us seriously. Our technology and security operations run under a formal Information Security Program maintained to the standards used in regulated environments. The sections below describe how that program applies to this website and the data we handle.

Security Governance

Security is overseen by a Security Governance Team led by the CISO, which meets regularly to advise on and prioritize the Information Security Program. Administrative, technical, and physical safeguards are maintained to align with applicable requirements, standards, and best practices, and security policies are reviewed and approved on a recurring basis. Risk is assessed on a multi-faceted basis through vulnerability assessments, penetration testing, and security reviews, with risk treatments aligned to security and business objectives.

People Security

Background checks. Reference checks are standard for personnel; criminal, credit, immigration, and security checks are performed where local law permits, varying by position and country.

Security training. All employees and contractors complete security training at orientation covering acceptable use and the code of conduct, with role-based training addressing secure coding, phishing, ransomware, and social engineering.

Operational Security

Access management. Access follows least-privilege and need-to-know principles. All personnel use multi-factor authentication and strong, uniquely generated passwords managed through approved password managers. Privileged access undergoes recurring recertification reviews, and access attempts are logged.

Vulnerability management. Vulnerabilities identified through commercially available tools, automated and manual penetration efforts, quality assurance processes, software security reviews, and external reports are logged, prioritized by severity, assigned to owners for tracking, and verified upon remediation.

Malware prevention. Anti-malware protections are deployed across managed laptops and servers, including link-checking services that screen URLs before they are opened.

Monitoring and alerting. Monitoring, alerting, and response capabilities are automated. Engineers and administrators are alerted to anomalies, application attacks, elevated error rates, and abuse scenarios, with predefined thresholds triggering responses such as traffic blocking and quarantine.

Infrastructure. Infrastructure primarily uses Microsoft Azure and other major cloud providers in US regions, with data kept within US cloud regions. Cloud data centers provide physical security controls including electronic access cards, biometrics, 24/7 camera monitoring, intrusion detection, and redundant power and environmental systems.

Encryption. Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Encryption keys are managed through cloud key management services with rotation schedules based on sensitivity, and TLS certificates are renewed regularly.

Recovery and availability. Systems are built on highly redundant components with regular, encrypted, and monitored backups, and recoverability is tested periodically.

Data Security

This website. getstartupfunding.com is served as static content with no public login, database, or content management system, which removes the most common classes of website attack.

Application data. Funding applications and meeting scheduling are handled through Microsoft 365 services (Microsoft Forms and Microsoft Bookings) within our enterprise environment. Access to application data is limited to the investment team under role-based access control, troubleshooting is performed without data access where possible, and any necessary access is temporary and revoked afterward.

Audit trails. Infrastructure changes and production authentication events are logged for auditing, and only authorized team members can access production systems.

Retention and destruction. Personal information is disposed of in accordance with our Privacy Policy and applicable agreements, including destruction of personal data upon verified request where retention is not legally required.

Application Security

Software supporting our operations follows a secure software development lifecycle: all code is kept in version-controlled repositories protected by strong credentials and multi-factor authentication, changes require peer review and continuous integration testing, and releases are logged and archived. Security testing follows the OWASP Testing Guide methodology, this website leverages modern browser protections against Cross-Site Scripting (XSS), clickjacking, and other code injection attacks (including HSTS and a Content Security Policy), and third-party security firms independently verify applications on a regular basis.

Network Security

Network and application firewalls restrict inbound traffic to explicitly authorized sources, and threat detection systems identify and block anomalous traffic patterns and malicious actions.

Third-Party Vendor Management

Before onboarding, third-party suppliers are assessed for their security and privacy practices relative to the scope of data they would access, and suppliers must execute appropriate security, confidentiality, and privacy contract terms.

Regulatory Compliance and Privacy

Our technology operations maintain SOC 2 compliance adhering to the standards set by the American Institute of Certified Public Accountants (AICPA) for service organizations (SSAE 18), verified through external audit. Personal data is never sold to third parties, and privacy considerations guide how systems are designed and operated. See our Privacy Policy for how we handle personal information.

Reporting a Vulnerability

We appreciate responsible disclosure. If you believe you have found a security vulnerability on this website, report it to legal@getstartupfunding.com with enough detail to reproduce the issue. Please do not access data that is not yours, degrade the service, or publicly disclose the issue before we have had a reasonable opportunity to address it.

Get Startup Funding logo

Investing into founders
since 2012.

SOC 2 logo

Explore

  • For Founders
  • For Investors
  • Portfolio
  • Blog

Connect

  • LinkedIn

Legal

  • Terms
  • Privacy
  • Accessibility
  • Security
  • Disclaimers
  • Cookie preferences

Get Startup Funding invests its own capital. Nothing on this website is an offer to sell or a solicitation to buy any security, or investment, legal, or tax advice. Submitting an application does not guarantee a response, funding, or any outcome. Early-stage investing involves substantial risk, including the possible loss of the entire investment, and past performance does not guarantee future results.

Copyright © 2026 Get Startup Funding. All rights reserved.
Get Startup Funding™ and the Get Startup Funding logo are trademarks of Get Startup Funding. Yahoo Finance, GOBankingRates, TechBullion, gener8tor, Microsoft, Google, LinkedIn, and all other third-party names and logos are trademarks of their respective owners, are used for identification purposes only, and do not imply affiliation with or endorsement of Get Startup Funding.