Pilot service summary
What DealVeto handles, the safeguards in place today, where requested AI features send context, and what must be agreed before a customer engagement begins.
- Policy basis
- September 1, 2026
- Operator
- Skor Technologies
- Region
- United States
- Contact
- legal@dealveto.com
Plain-language pilot summary — not a security certification, audit report, DPA, SLA, or replacement for signed pilot terms. Customer-specific requirements are agreed before kickoff.
01Current snapshot
Public-policy commitments for the pilot service
Encryption
Transit + managed at rest
Provider-managed safeguards for the pilot service
Access
Authenticated
Database access controls and invite-only pilot access
AI training
No shared training by default
Customer deal content is not a shared-model training corpus by default
Deletion
Manual review
Request scope and timing are verified before execution
02Information handled
Only what supports the service
Account information
Privacy Policy §1Name, work email, company, professional role, and account credentials. Passwords are stored as cryptographic hashes, never in plain text.
Deal information
Privacy Policy §1–2Property addresses, financial assumptions, program inputs, customer-authorized calibration material, and analysis outputs entered for the service.
Service and security data
Privacy Policy §1Feature usage, session duration, device/browser information, and IP address for operation, rate limiting, fraud prevention, and security.
03Safeguards today
Enforced and operating boundaries
Transport and storage
Privacy Policy §7Encryption in transit and managed-provider encryption at rest.
Access controls
Privacy Policy §7Authenticated access, database access controls, invite-only pilot access, and workspace configuration review.
Calculation authority
Privacy Policy §4Deterministic calculations and the user-approved cost basis remain authoritative; AI explains and recommends.
Change control
Pilot operating commitmentAssistants cannot silently modify saved deal data or an approved basis. External evidence changes the basis only after team acceptance.
04AI and service-provider boundaries
Requested feature context, not a hidden data pool
Minimum requested context
Privacy Policy §3Only context required for the requested AI-assisted feature is transmitted to the applicable provider.
Shared training default
Privacy Policy §4Private deal content is not used to train a shared cross-customer DealVeto model by default.
Customer-specific tuning
Privacy Policy §4Any future customer-specific fine-tuning requires explicit opt-in, a defined dataset, evaluation, versioning, and a reversible off-ramp.
Netlify
Infrastructure processor
Application hosting and server runtime
Web requests, including submitted feature payloads, pass through the hosting runtime as needed to serve the requested feature.
Supabase
Infrastructure processor
Authentication and application database
Account, workspace, deal, and authority records are processed for the signed-in service. A specific project region is confirmed privately before kickoff, not promised here.
Anthropic
AI processor or gateway
AI-assisted extraction and responses
Requested intake/document content or bounded assistant context is transmitted only when the applicable configured feature is invoked.
OpenAI or an approved compatible gateway
AI processor or gateway
Requested Veto decision-assistant response
The message, up to ten prior turns, specialist purpose, and bounded deal/economic context are transmitted for the requested answer. Direct Responses API requests set store=false.
Cal.com
Optional scheduling integration
Optional public-site scheduling
The scheduler loads only after a visitor chooses it; booking information is submitted directly to Cal.com.
Google Maps Platform
Map integration
Optional address search and interactive site-map context
Typed addresses, selected coordinates, map viewport, and normal browser request metadata may be sent when a Google map feature is invoked.
MapTiler
Map integration
Optional interactive maps, address search, and site-plan context
Address queries, selected coordinates, map viewport, and normal browser request metadata may be sent when a MapTiler feature is invoked.
Regrid
Licensed property-data provider
Optional parcel lookup
A selected latitude/longitude and bounded parcel lookup parameters are sent through an authenticated server route when invoked.
U.S. Census Bureau
Public data source
Address geocoding and geographic context
A requested address or selected coordinates are sent to the public geocoder when the lookup is invoked.
FEMA
Public data source
Flood-hazard and effective-panel screening
Selected coordinates or the accepted parcel boundary are sent to official public map services for the requested screen.
USGS
Public data source
Terrain/elevation screening
Selected point or bounded parcel-sample coordinates are sent to the public elevation service for the requested screen.
Texas Geographic Information Office (TxGIO)
Public data source
Texas parcel candidate lookup
Selected Texas coordinates and bounded parcel-identification parameters are sent to the public map service when invoked.
City of Dallas public zoning source
Public data source
Optional City of Dallas zoning context
Selected coordinates are sent only for an applicable requested City of Dallas zoning lookup. Any enabled DCAD appraisal lookup uses a separately approved imported snapshot in the application database, not a live county request.
05Lifecycle and rights
Retention, export, and deletion
Active account
Privacy Policy §5Account and deal data are retained while the account is active.
After deletion
Privacy Policy §5Deletion requests enter a manually reviewed workflow. Scope, legal/security holds, private evidence, and completion timing are verified before irreversible execution; no immediate-completion promise is made.
Audit history
Privacy Policy §5DealVeto authority and audit events may be retained for up to two years for security and compliance. Provider runtime logs follow the applicable provider and contracted control configuration.
Customer rights
Privacy Policy §6Customers may request access, correction, deletion, consent withdrawal, and JSON export of deal data.
Agree before kickoff
- Approved users, workspace, and customer-provided data scope
- AI-assisted features permitted for the engagement
- Retention, deletion, export, and offboarding requirements
- Any provider review or additional contractual security requirements
Not claimed by this summary
- SOC 2, ISO 27001, HIPAA, or another third-party security certification
- Customer-managed encryption keys or non-US data residency
- Production SSO, custom retention automation, or enterprise compliance controls
- Automated or immediate account-data deletion before private scope and authority verification
- A contractual DPA, security addendum, uptime SLA, or completed customer risk assessment