Security and data protection at EcoSync

Written for the person who has to sign off on this - whether that is a procurement team at a university, a grant officer, or a founder deciding what to put in a data room.

Separation between organisations

The most common question, and the one worth answering first. An incubator's workspace holds its programmes, its applications, its startups and its funding, and another incubator cannot see any of it.

That is not a permission that could be misconfigured. Each organisation's data is separated at the point it is stored, so there is no view in which one centre's cohort appears alongside another's.

  • Your programmes, applications, startups and funding are visible to your team only
  • A person who works with more than one incubator switches between workspaces and sees each one separately
  • Nothing about your cohort is published outward unless you choose to publish it

Who can see what, inside your own organisation

Roles decide what somebody can do in each area of the portal - view, add, change, remove, or manage it outright - and you can override that for one person where a role is not the right shape.

In practice that is what lets a finance officer work on disbursement without touching evaluation, or a junior colleague process applications without the authority to approve one.

Set per person, not per job title

A role is a starting point rather than a cage. Where somebody's actual job does not match any role you have, you change it for them without inventing a new role.

Refused attempts are recorded

Every denial is logged next to every status change. That is what demonstrates to an auditor that the controls were enforced rather than merely configured.

Encryption and how data moves

Data is encrypted in transit and at rest. Files you upload - application documents, pitch decks, evidence - go to encrypted storage rather than sitting on an application server.

Payments are handled by the payment provider rather than by us: card details are never stored on the platform and never reach our database.

The record of what happened

Applications, tasks, funding actions, announcements and permission denials are all recorded with who did it and when, and evaluation keeps each panel member's individual scores rather than only the average.

That matters most when somebody asks you to account for a decision months later - a rejected applicant, a funder reviewing a disbursement, or an internal review of how a cohort was selected.

Your own data, as an individual

Your profile is a public page and is meant to be found. Everything else is not: documents, metrics and deal materials are shared deliberately, with a programme you have applied to or an investor you are in a deal with, and permissions are set per record rather than globally.

Analytics can be turned off from the cookie policy page, and when it is off no analytics script loads at all.

Questions people actually ask

Can another incubator see our applications or startups?

No. Each organisation's data is separated at the point it is stored, so there is no view in which another centre's cohort appears alongside yours. It is not a setting that can be misconfigured.

Is data encrypted?

Yes, in transit and at rest. Uploaded files go to encrypted storage. Card details are handled by the payment provider and are never stored on the platform.

Can we restrict what individual team members can do?

Yes. You set what each role can do in each area of the portal, and override it for a specific person where a role is not the right shape. A finance officer can work on funding without touching evaluation.

Do you have SOC 2 or ISO 27001?

We do not hold those certifications today, and we would rather say so than imply otherwise. What we can do is show you exactly what is recorded, who can reach it, and how it is separated - bring us the specific requirement and we will map it against what exists.

What is recorded about what our team does?

Applications, tasks, funding actions, announcements and permission denials, each with the acting person and a timestamp. Evaluation retains each panel member's individual scores rather than only the aggregate.

Who owns the data we put in?

You do. Your cohort data, documents and records are yours, and publishing any of it outward is a choice you make rather than a default.

Bring us the requirement

If you have a specific security or compliance question - a procurement checklist, a funder's condition, a data-handling policy - send it and we will map it against what actually exists rather than guess.

Talk to us

Ready to Join
the Ecosystem?

Book a demo

EcoSync is a product of Opernova Technologies LLP.

Running an incubator or accelerator? EcoSync for incubators

© 2026 Opernova Technologies LLP. All rights reserved.