Security
The wall is the control
A deal room holds precisely what a company would least like to see forwarded. Permissions are set per document and per party, never per folder — the folder is filing; the document is the confidential thing.
For your security review
This page describes the controls as they’re built. Where a control is negotiated under an enterprise agreement, we say so, and we’ll answer your questionnaire directly rather than point you back here.
Controls
What is enforced, and where
Per-document walls
A party is admitted against named documents. Withdrawing one withdraws it, including from a link already sent.
Release on execution
Gated material is held by the record until its condition is met. The NDA executed, not reported as executed.
SSO and provisioning
Single sign-on with SCIM provisioning for internal staff, under the enterprise agreement.
Watermark and download control
Released documents can be watermarked per recipient and their download withheld.
Region-pinned storage
The document store and its backups pinned to a chosen region.
Scheduled audit export
The trail exported on your schedule, in a form your auditors can read without us.
The audit trail
Who saw what, and when
Every release, download and permission change is recorded against the mandate. When a client asks who had the CIM before the leak, the answer is a query, not an investigation.
Questions we are asked
Before the questionnaire
Where does the data sit?
In the region you choose. Region-pinned storage is part of the enterprise agreement, and the pin covers the document store and its backups alike.
Is our material used for training?
No. We embed documents so the record can answer questions about itself; we don't use them to train models.
How are external parties admitted?
Against named documents, by an adviser on the mandate. Buyers and counsel never get a general login to your firm.
What happens at completion?
Access falls away with the mandate, and the record stays readable and exportable to the firm that held it.