← Back to DealCause

Security & data handling

Last updated: August 11, 2026.

Current operating model: fixed-scope, no-platform diagnostic. No CRM integration, production-system access, privileged buyer credentials, code installation, browser extension or agent deployment is required.

Data minimization

DealCause is designed around a bounded sanitized or pseudonymized historical evidence pack. Do not provide passwords, credentials, API keys, secrets, payment-card data, government IDs, health data, classified/CUI/export-controlled material, unnecessary personal data, or raw production access.

AI-processing gate

Real confidential client data is not automatically placed into a personal ChatGPT workspace. Before production processing, DealCause verifies the applicable data-control posture and the buyer's contractual and security requirements. If residual personal data or business-grade contractual assurances are required, processing pauses until an approved path is agreed.

Storage, retention and subprocessors

The exact storage/transfer method, retention period, return/deletion timing and relevant third-party providers are frozen for the actual engagement before intake. DealCause does not publish a universal retention or subprocessor promise before the production path is known.

Current assurance status

SOC 2: not held / not claimed.
ISO 27001: not held / not claimed.
ISO 42001: not held / not claimed.
DealCause penetration-test report: not held / not claimed.
Cyber liability insurance: not claimed unless later documented.

DealCause will not display a trust badge, compliance claim, customer logo or assurance statement without evidence.

Confidentiality

Buyer data is used only for the agreed engagement. Buyer identity, evidence, findings, testimonial or case study are not published without explicit written permission.

Incidents and continuity

Accidental receipt of prohibited or materially sensitive data triggers stop-work on the affected material, containment, buyer notification when appropriate, a sanitized replacement request, and a documented recovery path. If an approved provider becomes unavailable, DealCause pauses rather than silently moving client data to an unapproved tool.

Procurement questions

Security and procurement answers are given as YES + evidence, NO, NOT APPLICABLE or UNKNOWN / pending buyer-specific review. A future plan is never represented as a current control.

Contact

dealcausehq@gmail.com