Trust Center / verified scope

Confidential records need clear controls.

This page describes the controls and workflow boundaries we can verify in the current DealForge product. It intentionally avoids unsupported security, certification, and data-processing claims.

Last updated August 20, 2026

01 / Security approach

Access is checked where work happens.

Authenticated workspaces

Product workspaces require authenticated access. Sensitive workflow operations check the caller against assigned workspace membership before proceeding.

Deal-scoped operations

Deal records, GL uploads, evidence review, and financial-pack actions are evaluated within the related workspace and deal context.

Controlled buyer-ready status

A financial evidence pack stays non-buyer-ready until an authorized workspace owner or admin records controller/CFO sign-off for that pack version.

Security controls are documented and continuously reviewed. We do not state encryption details, certifications, MFA, SSO, penetration testing, audit export, or a specific security SLA here because they are not verified by the current public product configuration.

02 / Confidentiality & access

Assigned permissions frame access.

DealForge is designed around least-privilege direction: access is controlled by assigned workspace and deal permissions, and sensitive operations re-check that relationship rather than relying only on a page-level gate.

Working evidence is separated from buyer-ready status.

The available financial evidence-pack workflow separates preparation from buyer-ready status. An authorized workspace owner or admin must record controller/CFO sign-off before the specific pack version becomes buyer-ready.

We do not represent buyer-group permissions, watermarking, download controls, or a separate buyer data-room control set as available features on this page.

03 / Data handling

Source first. Review before release.

Drafts do not replace evidence.

The QoE narrative and bridge are generated by rule-based calculation from the account summaries you upload, not by an AI model, and are treated as a source-led draft for review. Deterministic validations remain separate from narrative or suggested outputs, and the current financial evidence-pack workflow does not automatically publish results to buyers.

No model, no training claim.

No AI model is used anywhere in the QoE generation or evidence workflow, so no uploaded customer data is sent to or used for training any model.

04 / Retention & deletion

Deletion is scoped to the work record.

The GL upload workflow supports authorized workspace users removing an uploaded GL file and its related derived account summaries and exceptions. Retention and deletion are handled in the context of the related workspace and deal rather than through a public universal schedule.

No invented retention period.

DealForge does not publish a default retention duration on this page. Retention, deletion, and legal-hold information is available on request and should be confirmed for the specific customer relationship and transaction.

Request retention or deletion information

05 / Vendor transparency

Current verified project services.

Last reviewed August 20, 2026. This is a verification-limited public service list, not a contractual legal subprocessor schedule.

ServiceVerified role in this project
ConvexApplication backend, authentication integration, database/runtime, and file-storage APIs used by DealForge.
VercelFrontend deployment and hosting platform used for the DealForge web application.
PostHogProduct analytics library included in the web application.

06 / Incident response & disclosure

Report concerns through a controlled channel.

To report a potential security issue or request responsible-disclosure guidance, email the DealForge team. Do not send customer records, credentials, access tokens, or other sensitive files by email.

Responsible disclosure

info@nikah-ai.com

Include a concise description, affected URL or workflow, and safe reproduction steps. We do not promise a specific response or remediation SLA on this page.

What we do not claim

DealForge assists organization and review. It does not decide the deal.

DealForge does not provide legal, tax, accounting, cybersecurity, sanctions, or transaction advice. It does not promise a complete or risk-free diligence outcome. Customers and their qualified advisers remain responsible for review, conclusions, and decisions.

    Trust Center | DealForge