Mownt
SECURITY & COMPLIANCE

Compliance is enforced. Not just documented.

Mownt enforces 506(b) and 506(c) gating server-side, tracks every Form D filing, and maintains an append-only audit log of every investor-facing action. SOC 2 Type II is in progress, expected Q3.

HOW COMPLIANCE WORKS ON MOWNT

Server-side enforcement on every action.

Each of the four pillars below runs on the server and writes to the audit log. A misconfigured browser, a forwarded link, or a copy-paste of a private deal URL cannot bypass them.

506(b) GATE
30-day relationship attestation, enforced before deal access.

Every prospective investor must clear a substantive-relationship gate before a private 506(b) deal page resolves. The clock is tracked per investor on the server. The page returns a sealed state until the gate clears — there is no client-side toggle that can bypass it.

506(c) GATE
Accreditation verification with non-accredited investor cap.

506(c) deals require verified accreditation. Mownt supports the SEC 2024 bright-line ($200k+ investment) workflow alongside income/net-worth verification. The 35-investor non-accredited cap is tracked server-side per raise and enforced at admission time.

FORM D
Filing window tracked from first sale, surfaced on the dashboard.

The 15-day Form D countdown starts when the first soft commit converts to a sale. The deadline is shown on the operator dashboard and on the deal page header until the filing is logged. Amendments and annual updates surface the same way.

AUDIT LOG
Append-only event log, exportable for your counsel or the SEC.

Every admission, every gate clearance, every soft commit, every status change writes to an append-only audit log keyed to the investor and the deal. The log is exportable as CSV with a signed hash so a third party can verify nothing was rewritten.

SOC 2 TYPE II

In progress. Expected Q3.

Server-side compliance enforcement is our concrete differentiator today. SOC 2 Type II lets enterprise procurement check the box; the underlying control set — access management, change control, encryption at rest and in transit, vendor risk — is already operational and audit-ready.

We will publish the Type II report once issued. Until then, operators with procurement requirements can request the current control matrix and the Type I bridge letter when available.

Encryption at rest and in transit
Role-scoped access & session management
Change control & deploy review
Vendor risk & subprocessor registry
DATA & ACCESS

Your data, your tenancy, your export.

Operators own their pipeline, their soft-commit history, their audit log, and the documents their investors upload. We treat data export as a first-class workflow — not a friction point on cancellation.

Data residency

Operator and investor data live in a US-region Postgres database with row-level security. Every query that crosses the operator boundary is filtered by the authenticated user's operator_id on the server.

Investor access controls

Deal access is granted explicitly per investor by the operator. Public deal pages return a 404-equivalent until the relationship gate clears. Investor portal sessions are scoped to the investor's own deals — no cross-tenant data leakage.

Document vault

PDFs and KYC uploads sit behind Supabase storage with operator-scoped policies. Investor uploads (drivers license, accreditation letter) are isolated per investor and per operator. No public URL paths.

Export anytime

Operators can export investor pipeline, soft-commit history, document inventory, and the full audit log as CSV or PDF at any time. Cancellation does not lock data — the export remains available through the closure window.

INCLUDED ON EVERY TIER

No security claim hidden behind a higher tier.

The six items below are the same on every plan, from Launch Mode through Pro. Compliance enforcement is not an add-on; it is the product.

All compliance enforcement is on every tier
506(b) gate, 506(c) workflow, append-only audit, concurrent-solicitation lock — never gated behind an upgrade.
Setup is free
No security claim is hidden behind a separate onboarding SKU. The same hardened defaults ship to every tenant.
Data import is free
CSV and GHL imports ship on every paid tier. Importing your existing investor list does not require a paid integration upgrade.
Data export is free
Cancel anytime and keep your CSV, PDF, and full audit log. Lock-in is incompatible with a compliance promise.
Email support on every tier
Security and compliance questions are answered at the same SLA as billing — including on the free tier.
12-month price-lock
Your sign-up rate is locked for 12 months. New-customer pricing will not retroactively change yours mid-raise.
PROVENANCE

Built by an active CRE GP — not a tech outsider.

Urban Sun Capital — our founder’s own firm — is the alpha customer. Every release ships on a real raise first. Every roadmap item starts as a real GP problem. The compliance scaffolding on this page is the same scaffolding that runs Urban Sun Capital’s investor pipeline today.

ALPHA CUSTOMER
Urban Sun Capital

Active multifamily and value-add CRE sponsor. Runs every raise on Mownt — compliance, pipeline, documents, soft commits, audit log.

READY TO REVIEW THE COMPLIANCE POSTURE?

Apply for early access — we’ll send the full controls breakdown.

Tell us a bit about your raise and your procurement requirements. We’ll send the tier that fits and the current control matrix together.

Apply for early access