Security & Verification Posture
High-stakes M&A and private equity deal rooms require uncompromised, verifiable confidentiality. Client engagements run with zero-retention routing enforced, and every record carries cryptographic proof by default.
Zero-Retention Model Routing (Fail-Closed)
Engagements run with zero-data-retention routing enforced: requests are served only by providers holding zero-retention agreements. If no zero-retention provider can serve a model, the request fails rather than silently falling back.
Never Used for Model Training
Your deal data is routed exclusively to zero-training provider tiers and contractually barred from entering any foundation or fine-tuning corpus. Customer data never crosses tenant boundaries.
PII Stripped on the Reasoning Channel · AES-256-GCM
A GDPR and NDPR anonymization layer scrubs personally identifiable data from the audit’s reasoning channel, and a name-blinded run redacts entity names with the residual measured on the record. Stored records are encrypted at rest via AES-256-GCM with versioned key rotation, and TLS 1.2+ in transit.
Org-Scoped Access · Expiring Links
Every audit is strictly scoped to its owner and organization through a single access predicate. Access is audit-logged, share links carry explicit time expiry (returning HTTP 410 past expiration), and retention is configurable per organization.
Verify the Record Without Us
A SHA-256 chain binds source set → claims → render graph → delivered bytes. RFC 3161 tokens from independent authorities are stored whole, allowing third-party CLI verification with no system access needed.