Security & tenancy

Hard tenancy walls. Soft tenant ergonomics.

Investa is multi-tenant from the database row to the URL. Every asset manager runs in their own isolated tenant — own data, own users, own branding, own subdomain or custom domain. Investigators can switch tenants. Investors cannot see each other.

01 · Tenancy model

One platform, many isolated worlds.

Each tenant is a self-contained world: its own users, roles, funds, fees, KYC packs, approval chains, branding and domains. Cross-tenant access only exists for our own platform-admin layer, and every cross-tenant action is logged.

Investa platform Multi-tenant control plane
Tenant A funds.northstar.com
Users148
Funds22
Investors3,182
AUM$28.4B
Tenant B portal.summitcap.sa
Users62
Funds9
Investors614
AUMSAR 4.2B
Tenant C access.meridian.ae
Users231
Funds34
Investors5,402
AUMAED 18.7B
Row-level isolation

Every row in every table carries a tenant_id. The query layer refuses cross-tenant reads without an explicit, audited grant.

Per-tenant encryption keys

Each tenant has its own KMS-managed master key. Compromise of one tenant does not affect another.

Branding & domain

Subdomain on investa.app or your own custom domain with our cert. Logo, colors, typography per tenant.

Optional dedicated cluster

Enterprise tenants can opt for a single-tenant deployment in their preferred region — KSA, UAE, EU.

02 · Roles & permissions

Two-line separation as a structural property.

Investa ships with eight built-in roles aligned to the desks of a fund management firm. Every role has a defined surface, a defined audit footprint, and explicit two-line separation between Risk, Compliance and Operations.

Role Read Approve Configure Cross-tenant
Tenant AdminFirm ownerAll in tenantBranding, users, integrationsNo
Fund ManagerFMAll in fund(s)Sub/red, fees, NAVFund parametersNo
OperatorOPAll in fund opsNAV imports, allocationsMappings, schedulesNo
FinanceFNLedger, feesJournals, period closeFee rules, ERP mapNo
ComplianceCOKYC, casesOnboarding, freezesRules, KYC packsNo
RiskRKAll read-onlyLimits, exceptionsRisk register, policiesNo
RMRelationshipOwn bookInitiate sub/redNo
System AdminInvesta staffAudit onlyBreak-glassTemplates, flagsYes — audited
03 · Compliance & certifications

Built for the regulators you actually report to.

SAMA

Saudi Central Bank

Cyber Security Framework v1.0. Aligned controls for outsourced cloud hosting and customer data residency.

CMA

Saudi Capital Market Authority

Investment Funds Regulations + Authorised Persons Regulations. Reporting templates aligned to CMA filings.

DFSA

Dubai Financial Services

Collective Investment Rules, Prudential Investment Insurance Banking. Tenant residency in DIFC region.

FCA

UK Financial Conduct Authority

SYSC, COLL, SUP source-books. Investa supports MIFID II reporting templates & transaction reporting.

ISO

ISO 27001 : 2022

Certified information security management. Annual third-party audit; statement of applicability available under NDA.

SOC

SOC 2 Type II

Reports issued annually, covering Security, Availability and Confidentiality. Available under NDA.

04 · Architecture

Deployed where your data is allowed to live.

We run primary clusters in KSA (Riyadh), UAE (Dubai) and EU (Frankfurt). Tenants pick a residency at provisioning; data does not leave the region without an explicit, signed consent path.

99.95%SLA · 30-day rolling
RPO ≤ 5 minCross-AZ replication
RTO ≤ 1 hrRegion failover drill quarterly
Pen-test 2×/yrExternal, scoped to tenant boundary
For your security team

Get the security pack.

ISO 27001 statement of applicability, latest SOC 2 Type II report, pen-test summary, DR run-book, sub-processor list, DPA template. Available under mutual NDA.