Institutional-grade controls explained in plain language. This page is for procurement, compliance, and IT diligence reviewers — content here is factual, conservative, and verifiable on request.
GP Capital does not claim third-party certifications it does not currently hold. Where a control is in place but not yet externally audited, this page says so. Where a control is on the roadmap, it is labelled as such. We will gladly walk an institutional counterparty through specifics under NDA.
GP Capital operates a wholesale capital platform serving sophisticated counterparties (lenders, family offices, sponsors, intermediaries). Platform access is permissioned, NDA-gated, and role-based. Public-facing material on this site is intentionally limited — operational and counterparty information lives behind authenticated access only.
Every counterparty user has exactly one role at a time (borrower, lender, family office, broker, internal team, admin, super-admin). Each deal-room access grant is a separate record with its own NDA / agreement status, visibility scope, and revocation timestamp. External users only ever see their own participation — never another lender's identity, response, mandate detail, or matching score.
Deal content, counterparty identities, and participant responses are confidential by default. Platform access is gated by an NDA / platform agreement. We process personal data in line with the Privacy Policy and operate under the Terms of Service, Platform Terms, and Disclosures.
A Data Processing Addendum (DPA) is available on request for institutional counterparties whose internal policy requires one.
Security researchers and counterparties who identify a potential vulnerability are encouraged to report it via the Security & Responsible Disclosure page or directly to the contact listed in our security.txt file. We aim to acknowledge reports within two business days.
For all other procurement / compliance enquiries, please contact info@gp-cap.com with your reviewer details and we will route to the right team.
The following PDFs are generated from the same factual content as this page and are safe to share with procurement / compliance reviewers.
Plainly: the DPA Request Form is a form, not an executed DPA. The executed institutional DPA is reviewed and signed on a per-counterparty basis under NDA. Request via the form or by emailing the contact above.