Authenticated workspaces
Product workspaces require authenticated access. Sensitive workflow operations check the caller against assigned workspace membership before proceeding.
Trust Center / verified scope
This page describes the controls and workflow boundaries we can verify in the current DealForge product. It intentionally avoids unsupported security, certification, and data-processing claims.
Last updated August 20, 2026
01 / Security approach
Product workspaces require authenticated access. Sensitive workflow operations check the caller against assigned workspace membership before proceeding.
Deal records, GL uploads, evidence review, and financial-pack actions are evaluated within the related workspace and deal context.
A financial evidence pack stays non-buyer-ready until an authorized workspace owner or admin records controller/CFO sign-off for that pack version.
Security controls are documented and continuously reviewed. We do not state encryption details, certifications, MFA, SSO, penetration testing, audit export, or a specific security SLA here because they are not verified by the current public product configuration.
02 / Confidentiality & access
DealForge is designed around least-privilege direction: access is controlled by assigned workspace and deal permissions, and sensitive operations re-check that relationship rather than relying only on a page-level gate.
The available financial evidence-pack workflow separates preparation from buyer-ready status. An authorized workspace owner or admin must record controller/CFO sign-off before the specific pack version becomes buyer-ready.
We do not represent buyer-group permissions, watermarking, download controls, or a separate buyer data-room control set as available features on this page.
03 / Data handling
The QoE narrative and bridge are generated by rule-based calculation from the account summaries you upload, not by an AI model, and are treated as a source-led draft for review. Deterministic validations remain separate from narrative or suggested outputs, and the current financial evidence-pack workflow does not automatically publish results to buyers.
No AI model is used anywhere in the QoE generation or evidence workflow, so no uploaded customer data is sent to or used for training any model.
04 / Retention & deletion
The GL upload workflow supports authorized workspace users removing an uploaded GL file and its related derived account summaries and exceptions. Retention and deletion are handled in the context of the related workspace and deal rather than through a public universal schedule.
DealForge does not publish a default retention duration on this page. Retention, deletion, and legal-hold information is available on request and should be confirmed for the specific customer relationship and transaction.
Request retention or deletion information05 / Vendor transparency
Last reviewed August 20, 2026. This is a verification-limited public service list, not a contractual legal subprocessor schedule.
| Service | Verified role in this project |
|---|---|
| Convex | Application backend, authentication integration, database/runtime, and file-storage APIs used by DealForge. |
| Vercel | Frontend deployment and hosting platform used for the DealForge web application. |
| PostHog | Product analytics library included in the web application. |
06 / Incident response & disclosure
To report a potential security issue or request responsible-disclosure guidance, email the DealForge team. Do not send customer records, credentials, access tokens, or other sensitive files by email.
Responsible disclosure
info@nikah-ai.comInclude a concise description, affected URL or workflow, and safe reproduction steps. We do not promise a specific response or remediation SLA on this page.
What we do not claim
DealForge does not provide legal, tax, accounting, cybersecurity, sanctions, or transaction advice. It does not promise a complete or risk-free diligence outcome. Customers and their qualified advisers remain responsible for review, conclusions, and decisions.