Security & Controls
Enterprise-grade infrastructure designed for confidentiality and reliability.
Two-Pass Fact Check
Every deliverable is fact-checked against source documents before delivery. Numbers verified, conflicts flagged.
No Data Used for Training
API-only LLM access with store: false. Your documents are never retained by AI providers for training or logging.
Email Audit Trail
Every request and deliverable flows through email, creating a natural compliance trail. No shadow AI usage.
Cost Caps
Per-deliverable budget caps prevent runaway API spending. Override path available for high-priority requests.
Duplicate Prevention
Database-level locks prevent re-sending deliverables. Deduplication across conversations.
Encryption at Rest
Full-disk encryption via BitLocker (AES-256) on all DVP devices. Database and files encrypted at the volume level.
Encryption in Transit
All API calls use TLS 1.2+ encryption. Microsoft Graph and OpenAI enforce HTTPS.
Single-Tenant Azure
Azure AD app registration with client credential flow. No cross-tenant access. Your data stays in your tenant.
Secret Rotation
API keys and credentials rotated on a regular schedule. User-scoped storage, inaccessible to other accounts.
Domain Allowlist
Outbound email restricted to approved domains only. Prevents accidental delivery to unauthorized recipients.
Safeguards
Two-pass fact check corrects numbers against source
Cost caps prevent runaway API spending
Duplicate prevention stops repeat deliveries
Email-based audit trail for compliance
API-only LLM access — no consumer data sharing
Practical Limits
AI can miss context, nuance, or edge cases
Not a replacement for legal, accounting, or tax review
Human review remains mandatory before external use
Best positioned as an 80-90% first draft
Final judgment, legal opinions, and external communications remain with the deal team
Isolated Storage
Client documents stored in per-company directories. No commingling of data between clients.
Configurable Retention
Default 90-day retention. Files can be purged on request at any time.
Deletion on Request
All client data permanently deleted upon written request within 24 hours.