Secure document sharing for funds and family offices

Positions, updates and side letters. Seen by the right people only.

An LP update goes to forty inboxes. One of them forwards it. Now your positions are a screenshot in someone else's group chat. GCN.ONE sends each document to a named person, encrypted in the browser before it leaves, with an expiry you set and a record of every open.

Send a file now See pricing
A distribution list is not a confidentiality control

Quarterly letters, position summaries and side letters go out to a list, and a list is only as private as its least careful member. One forward, one shared laptop, one personal address that crept onto the list, and terms you negotiated privately are circulating.

The usual fixes do not really fix it. A password-protected PDF travels with its password in the same thread. A consumer cloud link works for anyone holding it, indefinitely. Both were built for convenience, never for confidentiality.

How a quarter works with GCN.ONE
1
Send to named people, not to a list
Each LP, adviser or counterparty gets their own access. Encryption happens in your browser, so the servers hold ciphertext they cannot read.
2
Set when it stops working
Give the update a life - to the end of the quarter, or to the end of the week. When it expires the encrypted data is deleted, and you can revoke any individual recipient before then.
3
See who opened what
Every open and download is timestamped per recipient. You can tell which LPs have read the update and which have not, without having to ask.
Built for investor reporting
Named people, not a mailing list
Access is granted per person, so revoking one LP does not disturb the other thirty-nine.
Expire it after the quarter
Set the expiry when you send. When it passes, the encrypted data is permanently deleted - no archive, no backup, nothing to surface later.
Know who has read it
Opens and downloads are recorded per recipient with timestamps, so a reminder goes only to the people who have not read it yet.
A signed record when you need one
For any downloaded document you can issue a delivery certificate: cryptographically signed, timestamped, and verifiable by anyone without an account.
The delivery record, in plain terms

Every completed delivery can produce a delivery certificate - a signed record of what was delivered, to whom, and when. Because the signature is cryptographic, an LP, an auditor or an administrator can verify it at our public Verify page without taking our word for it, and without a GCN.ONE account.

Our audit log is tamper-evident and publicly anchored, so the history behind a certificate cannot be quietly rewritten, by us or by anyone else. Whether a particular notice requirement in a fund's own documents is satisfied is a question for those documents; we make no claim to be a qualified delivery service under eIDAS.

What we can and cannot see

Encryption happens in the browser and the keys never reach us, so we cannot read an LP update, a position summary or a side letter - there is nothing readable on our side to disclose. What the servers do see is metadata: sender, recipients, timestamps and sizes. All infrastructure runs in the European Union under EU jurisdiction and is built to GDPR standards.

Request our Data Processing Agreement (DPA)

Frequently asked questions

Yes. Add the recipients to one share and each of them gets their own access to it. You upload once; access, expiry and revocation stay per person.

No. They open the link in their browser and the document is decrypted there. You need a free account to send; they need nothing.

The encrypted data is permanently deleted. There is no archive and no backup copy waiting to be found in a later review.

We can only hand over what we hold, which is encrypted data we cannot decrypt. That is an architectural property, not a policy that could be changed quietly.
Try it on this quarter's update
A free account takes a minute. Send one document and see the record.