Hard tenancy walls. Soft tenant ergonomics.
Investa is multi-tenant from the database row to the URL. Every asset manager runs in their own isolated tenant — own data, own users, own branding, own subdomain or custom domain. Investigators can switch tenants. Investors cannot see each other.
One platform, many isolated worlds.
Each tenant is a self-contained world: its own users, roles, funds, fees, KYC packs, approval chains, branding and domains. Cross-tenant access only exists for our own platform-admin layer, and every cross-tenant action is logged.
Two-line separation as a structural property.
Investa ships with eight built-in roles aligned to the desks of a fund management firm. Every role has a defined surface, a defined audit footprint, and explicit two-line separation between Risk, Compliance and Operations.
| Role | Read | Approve | Configure | Cross-tenant |
|---|---|---|---|---|
| Tenant AdminFirm owner | All in tenant | — | Branding, users, integrations | No |
| Fund ManagerFM | All in fund(s) | Sub/red, fees, NAV | Fund parameters | No |
| OperatorOP | All in fund ops | NAV imports, allocations | Mappings, schedules | No |
| FinanceFN | Ledger, fees | Journals, period close | Fee rules, ERP map | No |
| ComplianceCO | KYC, cases | Onboarding, freezes | Rules, KYC packs | No |
| RiskRK | All read-only | Limits, exceptions | Risk register, policies | No |
| RMRelationship | Own book | Initiate sub/red | — | No |
| System AdminInvesta staff | Audit only | Break-glass | Templates, flags | Yes — audited |
Built for the regulators you actually report to.
Saudi Central Bank
Cyber Security Framework v1.0. Aligned controls for outsourced cloud hosting and customer data residency.
Saudi Capital Market Authority
Investment Funds Regulations + Authorised Persons Regulations. Reporting templates aligned to CMA filings.
Dubai Financial Services
Collective Investment Rules, Prudential Investment Insurance Banking. Tenant residency in DIFC region.
UK Financial Conduct Authority
SYSC, COLL, SUP source-books. Investa supports MIFID II reporting templates & transaction reporting.
ISO 27001 : 2022
Certified information security management. Annual third-party audit; statement of applicability available under NDA.
SOC 2 Type II
Reports issued annually, covering Security, Availability and Confidentiality. Available under NDA.
Deployed where your data is allowed to live.
We run primary clusters in KSA (Riyadh), UAE (Dubai) and EU (Frankfurt). Tenants pick a residency at provisioning; data does not leave the region without an explicit, signed consent path.
Get the security pack.
ISO 27001 statement of applicability, latest SOC 2 Type II report, pen-test summary, DR run-book, sub-processor list, DPA template. Available under mutual NDA.