Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To know what an AI investment platform can access, inspect the specific permissions on the connection—not just labels such as “connect” or “secure.” Check which accounts and records it can reach, whether it can take actions such as placing trades, what data may be sent to AI providers, how access is revoked, and what happens to stored copies. Use the checklist below to review the actual authorization screen and current vendor documentation before connecting an account or sharing private records.

1. List the data and actions the connection permits

Start with the consent screen, API scopes, and documentation for the exact connection you plan to use. Write down every data category it can reach, then separately record what it can do with that data.

  • Data: holdings, transactions, balances, fund or limited-partner records, private documents, research notes, and exports.
  • Actions: view, edit, share, export, delete, trade, or transfer.

Do not infer that an investment-focused product is read-only. Carta documents OAuth scopes with a read_ versus readwrite_ pattern, illustrating how access can be distinguished at the endpoint level: Carta’s authentication documentation. Trading 212 says users can choose API-key permissions that include read-only access or placing orders: Trading 212’s API-key permissions guide. These examples show why the exact scope names and enabled actions matter; they do not establish the permissions of another vendor’s integration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Find out whose permissions govern access

Ask whether the integration inherits the connecting user’s permissions, whether it is scoped to one account or an organization, and what happens when that user changes role or leaves the firm. A connection should not silently grant access to records that the user could not otherwise view.

Carta says an API application’s access matches the granting user’s access and checks that user’s current role. If the user loses permission to an endpoint after a role change, a request may return 403 Forbidden: Carta’s authentication documentation. AngelList says its MCP uses the same authentication and authorization infrastructure as its web app and can reach only data the user could see there: AngelList’s MCP documentation. Ask your vendor how those rules apply to the specific connection, account, and deployment you will use.

3. Verify organization, tenant, and document boundaries

For team or institutional use, determine how the platform separates customers and limits access to documents. Ask whether an investor-facing portal account is isolated from the management interface and from other investors’ records. Find out whether document access checks the requesting user, tenant, role, and document-level permission each time a file is delivered.

Prism’s trust-centre materials describe authenticated document delivery and portal access linked to an LP; its security page describes tenant isolation, roles, document controls, and auditability: Prism Trust Center and Prism security page. These are vendor descriptions, not independent verification. During diligence, ask for the current materials and confirm that the controls apply to your product tier and configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Ask what happens to data in AI features

Read-only access limits actions, but it does not settle what happens to information after the platform can read it. Ask the vendor to identify:

  • Which prompts, documents, holdings, and derived outputs are sent to model providers.
  • Whether information is retained, for how long, and whether it may be used to train models.
  • Which subprocessors receive data, and whether the answer varies by account tier.
  • Whether data is automatically included in every query or used only when a user selects it.

Kimpton’s security overview says users decide when vault documents and portfolio information are used as AI context: Kimpton’s security overview. Treat statements such as “never used for training” as vendor claims to verify in current privacy terms, contracts, and subprocessor disclosures. Ask for the terms that govern your account rather than relying only on a product-page statement.

5. Confirm revocation and data deletion

Locate the actual disconnect or revocation procedure before authorizing access. Ask whether revocation takes effect immediately, which tokens and connections it disables, whether imported copies are deleted, and how to request account deletion. Clarify whether already-exported data can remain in backups or logs and for how long.

AngelList describes a scoped token that can be revoked: AngelList’s MCP documentation. Kimpton’s materials describe revocable connections and say data associated with a disconnected portfolio is deleted: Kimpton’s security overview. Those public statements do not establish exact operational timing or the treatment of every copy for your account, so ask for the applicable contractual terms and a specific answer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Review assurance, monitoring, and evidence

Ask for the current trust-centre materials, security report, data-processing agreement, retention schedule, incident process, and audit or logging details. Check that the documents match the product, deployment, and use case under consideration; a general security page is not a substitute for reviewing the underlying materials.

Prism describes a trust centre and multiple security controls, which can help identify materials to request: Prism Trust Center and Prism security page. The Cloud Security Alliance recommends limiting maximum OAuth scopes for AI SaaS tools and monitoring OAuth-related events: Cloud Security Alliance research note. Apply those points by checking that the connection requests only necessary scopes and that your organization can review relevant authorization activity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use one comparison record for every platform

When comparing vendors, ask the same questions and record whether each answer is documented, contractual, or only verbal. This keeps a clear distinction between a stated control and an obligation you can rely on.

Assessment area What to record
Permission granularity Exact scopes and whether read and write permissions can be separated.
Data and account boundaries Reachable data categories, accounts, and organization-level limits.
Actions Whether the connection can edit, export, share, delete, trade, or transfer.
AI data handling Information sent to model providers, retention, training use, subprocessors, and user controls.
Identity and administration How user roles govern access, how administrators control access, and what happens when a user’s role changes.
Revocation and deletion How to disable access, how quickly it takes effect, and what happens to copies, backups, and logs.
Isolation and auditability Tenant and document boundaries, available logs, and who can review them.
Assurance Availability and date of current independent reports, contractual terms, and security documentation.

Before you authorize a connection

  1. Open the vendor’s actual authorization screen for the intended account and record each requested permission.
  2. Compare the permissions with the data and actions your use case needs; decline or narrow any access that is not necessary.
  3. Check whose identity and role control access, including what happens after role changes or offboarding.
  4. Get written answers on AI data use, subprocessors, retention, revocation, and deletion for your account and plan.
  5. For organizational use, review current security materials and confirm tenant boundaries, document controls, and auditability with the vendor.

Most public evidence for individual vendor controls comes from the vendors themselves. Their pages establish what those companies say, not independent proof that a control works in every configuration. Verify current consent scopes, applicable contract language, and account-specific settings before sharing brokerage access, fund records, or private research.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.