← All solutions Solution · Trust and Investor Portal

External stakeholders read live records, not re-hosted PDFs.

Investor reporting is usually an assembly line that ends in email: statements exported, renamed, sent, and re-sent. On this platform an external stakeholder (a fund investor, a trust-office client, a customer completing KYC) is granted a scoped view of the live records: capital account, performance, documents. Every read is logged, and so is every denial.

Regulatory anchor Investor information under AIFMD Art. 23 as the substrate; evidence and document sharing for trust services; built on the platform's audit, tenant-isolation, and token architecture.
Platform state Available in platform
What it is

Three external surfaces, one grant-and-token substrate.

The portal is how the platform faces people who are not your employees. An investor granted access to a fund sees the fund's profile, their commitment and derived capital account, the NAV curve and IRR with a currency toggle, and the documents that concern them (notices, statements, reports) in seven investor-facing classifications. Downloads are checked against the grant on every request.

The same substrate serves two more surfaces: trust-office stakeholders reviewing shared evidence, and customers completing KYC questionnaires through a secure external page. One token architecture (hashed at rest, expiring, revocable), and three doors into precisely scoped slices of the same records.

Grants are per stakeholder, per fund, issued and revoked by your team from the fund's admin view. Revocation is immediate: the next read fails, and the failed read is logged too.

The core mechanism

External access is a grant over live data, not an export.

The traditional investor portal is a document dropbox: someone exports the quarterly statement, uploads it, and the portal's truth diverges from the system's truth the day after. The dropbox also cannot answer the questions investors actually ask: what have I paid in, what came back, what is it worth now.

Here the portal computes those answers from the fund ledger at read time. The capital account is derived from the same cash events the compliance team maintains; the IRR is calculated from the same dated flows the Annex IV projection reads. Nothing is exported to the portal, so nothing on the portal can go stale.

Isolation is enforced where it must be: at the database. Row-level security, with integration tests proving the six failure modes that matter (cross-tenant tokens, ungranted funds, cross-investor reads, ungranted documents, revoked grants mid-session, expired tokens), each denied, each logged.

How this module is different

Most portals re-host files. This one answers from the ledger.

Portals bundled with fund-administration suites host what the administrator uploads. Standalone data rooms host what anyone uploads. In both cases the portal is a copy, with a copy's failure modes: version confusion, stale figures, and no connection between what the investor sees and what the regulator receives.

On this platform the investor's view, the compliance team's records, and the regulatory filing are three readers of one dataset. When the ledger is corrected, all three are corrected. And because the portal rides the document platform rather than its own file store, an investor notice exists once (classified, versioned, access-checked) instead of once per channel.

The trust-office lineage matters here. The portal substrate was built for sharing evidence with external stakeholders under audit, and the investor surface inherited that discipline (logging, isolation proofs, rate limiting) rather than having security added at the end.

What it does not do yet

A reading room, deliberately.

The portal is read-only by design, and its authentication is deliberate too: access rides scoped, expiring, revocable tokens issued by your team, person by person. Portal-side multi-factor authentication for external users is not in product yet; until it is, token scope, expiry, rate limiting, and full read-logging are the containment.

There is no messaging channel and no self-service onboarding: investors do not register themselves; your team issues access. Notices flow through classified documents rather than chat.

Grant scoping today is per fund and gives the full investor view. A documents-only scope exists in the data model but is not yet enforced on every read path, so we do not sell it. When it ships, it ships honestly.

Next step

A discovery call, not a product demo.

You describe the compliance problem consuming the most of your team's time. We walk the platform through an example close enough to your operation that you can judge whether this way of modelling compliance fits how you want to work.

Book a discovery call →