Design Partner Pilot

Forwardable trust summary

Know what enters DealVeto.
Know where it goes.

A plain-language summary of the pilot service's current safeguards, AI context boundaries, external data flows, data lifecycle, and the requirements that still belong in a signed agreement.

Read the Privacy Policy
DealVetoSecurity & data handling

Pilot service summary

What DealVeto handles, the safeguards in place today, where requested AI features send context, and what must be agreed before a customer engagement begins.

Policy basis
September 1, 2026
Operator
Skor Technologies
Region
United States
Contact
legal@dealveto.com

Plain-language pilot summary — not a security certification, audit report, DPA, SLA, or replacement for signed pilot terms. Customer-specific requirements are agreed before kickoff.

01Current snapshot

Public-policy commitments for the pilot service

Encryption

Transit + managed at rest

Provider-managed safeguards for the pilot service

Access

Authenticated

Database access controls and invite-only pilot access

AI training

No shared training by default

Customer deal content is not a shared-model training corpus by default

Deletion

Manual review

Request scope and timing are verified before execution

02Information handled

Only what supports the service

  • Account information

    Privacy Policy §1

    Name, work email, company, professional role, and account credentials. Passwords are stored as cryptographic hashes, never in plain text.

  • Deal information

    Privacy Policy §1–2

    Property addresses, financial assumptions, program inputs, customer-authorized calibration material, and analysis outputs entered for the service.

  • Service and security data

    Privacy Policy §1

    Feature usage, session duration, device/browser information, and IP address for operation, rate limiting, fraud prevention, and security.

03Safeguards today

Enforced and operating boundaries

  • Transport and storage

    Privacy Policy §7

    Encryption in transit and managed-provider encryption at rest.

  • Access controls

    Privacy Policy §7

    Authenticated access, database access controls, invite-only pilot access, and workspace configuration review.

  • Calculation authority

    Privacy Policy §4

    Deterministic calculations and the user-approved cost basis remain authoritative; AI explains and recommends.

  • Assistants cannot silently modify saved deal data or an approved basis. External evidence changes the basis only after team acceptance.

04AI and service-provider boundaries

Requested feature context, not a hidden data pool

  • Minimum requested context

    Privacy Policy §3

    Only context required for the requested AI-assisted feature is transmitted to the applicable provider.

  • Shared training default

    Privacy Policy §4

    Private deal content is not used to train a shared cross-customer DealVeto model by default.

  • Customer-specific tuning

    Privacy Policy §4

    Any future customer-specific fine-tuning requires explicit opt-in, a defined dataset, evaluation, versioning, and a reversible off-ramp.

Netlify

Infrastructure processor

Application hosting and server runtime

Web requests, including submitted feature payloads, pass through the hosting runtime as needed to serve the requested feature.

Supabase

Infrastructure processor

Authentication and application database

Account, workspace, deal, and authority records are processed for the signed-in service. A specific project region is confirmed privately before kickoff, not promised here.

Anthropic

AI processor or gateway

AI-assisted extraction and responses

Requested intake/document content or bounded assistant context is transmitted only when the applicable configured feature is invoked.

OpenAI or an approved compatible gateway

AI processor or gateway

Requested Veto decision-assistant response

The message, up to ten prior turns, specialist purpose, and bounded deal/economic context are transmitted for the requested answer. Direct Responses API requests set store=false.

Cal.com

Optional scheduling integration

Optional public-site scheduling

The scheduler loads only after a visitor chooses it; booking information is submitted directly to Cal.com.

Google Maps Platform

Map integration

Optional address search and interactive site-map context

Typed addresses, selected coordinates, map viewport, and normal browser request metadata may be sent when a Google map feature is invoked.

MapTiler

Map integration

Optional interactive maps, address search, and site-plan context

Address queries, selected coordinates, map viewport, and normal browser request metadata may be sent when a MapTiler feature is invoked.

Regrid

Licensed property-data provider

Optional parcel lookup

A selected latitude/longitude and bounded parcel lookup parameters are sent through an authenticated server route when invoked.

U.S. Census Bureau

Public data source

Address geocoding and geographic context

A requested address or selected coordinates are sent to the public geocoder when the lookup is invoked.

FEMA

Public data source

Flood-hazard and effective-panel screening

Selected coordinates or the accepted parcel boundary are sent to official public map services for the requested screen.

USGS

Public data source

Terrain/elevation screening

Selected point or bounded parcel-sample coordinates are sent to the public elevation service for the requested screen.

Texas Geographic Information Office (TxGIO)

Public data source

Texas parcel candidate lookup

Selected Texas coordinates and bounded parcel-identification parameters are sent to the public map service when invoked.

City of Dallas public zoning source

Public data source

Optional City of Dallas zoning context

Selected coordinates are sent only for an applicable requested City of Dallas zoning lookup. Any enabled DCAD appraisal lookup uses a separately approved imported snapshot in the application database, not a live county request.

05Lifecycle and rights

Retention, export, and deletion

  • Active account

    Privacy Policy §5

    Account and deal data are retained while the account is active.

  • After deletion

    Privacy Policy §5

    Deletion requests enter a manually reviewed workflow. Scope, legal/security holds, private evidence, and completion timing are verified before irreversible execution; no immediate-completion promise is made.

  • Audit history

    Privacy Policy §5

    DealVeto authority and audit events may be retained for up to two years for security and compliance. Provider runtime logs follow the applicable provider and contracted control configuration.

  • Customer rights

    Privacy Policy §6

    Customers may request access, correction, deletion, consent withdrawal, and JSON export of deal data.

Agree before kickoff

  • Approved users, workspace, and customer-provided data scope
  • AI-assisted features permitted for the engagement
  • Retention, deletion, export, and offboarding requirements
  • Any provider review or additional contractual security requirements

Not claimed by this summary

  • SOC 2, ISO 27001, HIPAA, or another third-party security certification
  • Customer-managed encryption keys or non-US data residency
  • Production SSO, custom retention automation, or enterprise compliance controls
  • Automated or immediate account-data deletion before private scope and authority verification
  • A contractual DPA, security addendum, uptime SLA, or completed customer risk assessment

Review the current Privacy Policy and Terms for complete public language. Contractual requirements belong in the signed pilot agreement or an approved addendum.

Questions · legal@dealveto.com

Scope before access · Boundaries before reliance

Review your requirements before the first live pursuit enters the workspace.

Book a security review