DiligenceIQ — a product of AI Lighthouse Partners ← AI Lighthouse Partners
SecurityData handling · access · traceability

Built for confidential
deal environments.

A platform that touches a live data room has to answer three questions before it answers any others: where did this finding come from, who approved it, and what happens to our data.

01 / Data Ingestion, storage and retention

What happens to deal information.

01

Secure document ingestion

Documents are transferred into a controlled environment for the specific deal. Ingestion routes and supported formats are confirmed during technical onboarding.

02

Encryption in transit and at rest

Deal information is encrypted while moving and while stored. Cipher standards and key management are covered in the technical review.

03

Client data isolation

Each client's deal information is segregated. Evidence from one engagement does not inform another.

04

Retention and deletion

Retention periods and deletion procedures are agreed as part of engagement, including what happens at the end of a deal or a licence term.

05

Hosting and data residency

Hosting region and data-residency requirements are confirmed before onboarding, including where a specific jurisdiction is required.

06

Model training

Client data is not used to train shared models. Your deal information informs your deal.

02 / Access & Governance Who can reach what

Deal teams are not one undifferentiated group.

Access

User and role-based access

Access is granted per deal and per role, so team members see the evidence and outputs relevant to their part of the process.

Audit

Audit trails

Activity across the workflow is recorded — what was ingested, what was analysed, what was reviewed and by whom.

Contract

NDA and data-processing agreements

Engagements are covered by non-disclosure and data-processing agreements executed before any deal information is transferred.

Deployment

Deployment options, security architecture and integration with your existing data room are covered in a partner-led technical session as part of onboarding. Where your risk function has a standard assessment process, we work through it directly rather than asking you to accept assurances.

03 / Reliability How the system behaves when evidence is thin

The design question is not whether AI can be wrong. It is what happens when the evidence does not support a conclusion.

Separation

Evidence, inference and open questions stay distinct

A statement supported by a source document, an inference drawn across sources, and a gap in the record are three different objects in the output — not blended into one confident sentence.

Escalation

Weak evidence is flagged, not smoothed over

Where evidence is missing, partial or contradictory, it is raised as an issue or an evidence gap rather than presented as a finding.

Traceability

Findings link back to their source

Material findings and red flags connect to the supporting document, page, table or extract wherever it is available, so a reviewer can check the basis rather than take it on trust.

Human approval

Every output is a draft until a named person on the deal team approves it. Interpretation, challenge and the final recommendation are human responsibilities, and the platform is built to make that review possible rather than to make it unnecessary.

04 / Limits Stated plainly

What DiligenceIQ does not claim.

Overstated capability is a risk in itself. These are the boundaries, stated before a procurement process has to find them.

It does not complete diligence

It produces drafts and structured evidence for human review. It does not issue a professional opinion, sign off on a transaction or replace the deal team's judgment.

It does not replace specialist due diligence

Formal financial, legal, tax, regulatory, cyber and other specialist due diligence — and independent valuation where required — remain with qualified professionals.

It does not guarantee every risk is found

It widens document coverage and surfaces potential red flags earlier. It cannot warrant that every risk in a transaction has been identified.

It does not certify what it has not been given

Findings reflect the evidence available. Where a data room is incomplete, that is reported as an evidence gap rather than resolved by inference.

Specific security controls, certifications and contractual commitments are confirmed in writing during onboarding. We would rather set them out in a technical review than assert them on a web page.

Next step

Request a demo.

See how DiligenceIQ can be configured around your deal process, sector and diligence methodology. Partner-led, around 30 minutes.