SecurityYour deal data, your control

Your deal data.
Your control.

The questions your legal and infosec teams ask first: where did this finding come from, who approved it, and what happens to our data.

Deployment Two models, chosen at onboarding

Run it in our boundary, or entirely in yours.

Option 01 · Maximum isolation

Private cloud

ConfigurableRuns entirely within your own cloud boundary.
ConfigurablePrivate inference — deal data does not leave your environment.
ConfigurableHSM-backed key management, with post-quantum-ready vaulting available on request.
Option 02 · Fast to deploy

Secure SaaS

ConfigurableHosted within your national boundary, where the region is supported.
AvailableTenant-isolated, with organisation-scoped role-based access control.
AvailableZero-retention, zero-training model terms.
How this is confirmed

Deployment options, security architecture and integration with your existing data room are covered in a partner-led technical session as part of onboarding. Where your risk function has a standard assessment process, we work through it directly rather than asking you to accept assurances.

01 / Data Ingestion, storage, retention

What happens to deal information.

Read these as deployment-dependent. Which of the controls below apply, and how they are configured, follows the deployment model and the contract agreed at onboarding. They are described here to support a security review, not as a certification, and are confirmed in writing before any deal information is loaded.

Secure document ingestion

Documents are transferred into a controlled environment scoped to the specific deal. Ingestion routes and supported formats are confirmed during technical onboarding.

Encryption in transit and at rest

Deal information is encrypted while moving and while stored. Cipher standards and key management are covered in the technical review.

Client data isolation

Each client's deal information is segregated. Evidence from one engagement does not inform another under any configuration.

Retention and deletion

Retention periods and deletion procedures are agreed as part of engagement, including what happens at the end of a deal or a licence term.

Hosting and data residency

Hosting region and data-residency requirements are confirmed before onboarding, including where a specific jurisdiction is required.

Model training

Client data is not used to train shared models. Your deal information informs your deal.

02 / Access & Governance Access control

Deal teams are not one undifferentiated group.

User and role-based access

Access is granted per deal and per role, so team members see the evidence and outputs relevant to their part of the process.

Audit trails

Activity across the workflow is recorded — what was ingested, what was analysed, what was reviewed and by whom.

NDA and data-processing agreements

Engagements are covered by non-disclosure and data-processing agreements executed before any deal information is transferred.

03 / Reliability How the system behaves when evidence is thin

The design question is not whether AI can be wrong. It is what happens when the evidence does not support a conclusion.

Separation

Evidence, inference and open questions stay distinct

A statement supported by a source document, an inference drawn across sources, and a gap in the record are three different objects in the output — not blended into one confident sentence.

Escalation

Weak evidence is flagged, not smoothed over

Where evidence is missing, partial or contradictory, it is raised as an issue or an evidence gap rather than presented as a finding.

Traceability

Findings link back to their source

Material findings and red flags connect to the supporting document, page, table or extract wherever it is available, so a reviewer can check the basis rather than take it on trust.

Human approval

Every output is a draft until a named person on the deal team approves it. Interpretation, challenge and the final recommendation are human responsibilities, and the platform is built to make that review possible rather than to make it unnecessary.

04 / Limits Stated plainly

What DiligenceIQ does not claim.

Overstated capability is a risk in itself. These are the boundaries, stated before a procurement process has to find them.

It does not complete diligence

It produces drafts and structured evidence for human review. It does not issue a professional opinion, sign off on a transaction or replace the deal team's judgement.

It does not replace specialist due diligence

Formal financial, legal, tax, regulatory, cyber and other specialist due diligence — and independent valuation where required — remain with qualified professionals.

It does not guarantee every risk is found

It widens document coverage and surfaces potential red flags earlier. It cannot warrant that every risk in a transaction has been identified.

It does not certify what it has not been given

Findings reflect the evidence available. Where a data room is incomplete, that is reported as an evidence gap rather than resolved by inference.

Specific controls, certifications and contractual commitments are confirmed in writing during onboarding. We would rather set them out in a technical review than assert them on a web page.

Recommended next step

Put DiligenceIQ to the test.

Run it against a deal you have already completed, or start with one workstream on one live transaction. Compare time saved, evidence coverage, analyst effort, finding quality and IC readiness.