Trust

The answers your compliance reviewer will ask for.

Written to be forwarded. Every answer here is one you can send straight to the person at your firm who has to sign off, or to your client's counsel at NDA stage.

Application region

Frankfurt, Germany (fra1)

Database region

Frankfurt, Germany (eu-central-1)

Mail sub-processor

None

Who is the data controller and who is the processor?

You are the controller of the personal data you put into your workspace - your contacts, your counterparties, your notes. DealLaunch AI is the processor, acting only on your instructions. Our Data Processing Agreement records this and is available to sign before you upload anything.

Where is the data processed?

In the European Union. Application server functions run in Frankfurt, Germany (fra1), and the database, authentication and document storage sit in Frankfurt, Germany (eu-central-1) - the same city, so your deal data does not cross the Atlantic in the course of ordinary use. The two exceptions are named and narrow: the AI providers listed below are in the United States and receive only the specific text you submit for a draft or a summary, under the standard contractual clauses in their own terms, and never your document store or your pipeline.

Is workspace data separated between customers?

Yes. Every table carries the owning workspace and is protected by Postgres row-level security, so a query authenticated as one firm cannot read another firm's rows. Uploaded documents live in a private storage bucket reachable only through short-lived signed links.

Who at DealLaunch can see our deal data?

Nobody routinely. There is no customer-support console that reads your workspace. Direct database access is used only for maintenance and incident response, and we will tell you if your workspace was involved in an incident.

How is outreach sent, and does it touch your servers?

There is no mail sub-processor. Outreach is sent directly from your own mailbox - through Microsoft Graph, or through your firm's own SMTP server - using credentials encrypted with AES-256-GCM and never returned to the browser. Nothing you send is relayed through DealLaunch infrastructure, which means your firm's existing journaling and archiving still capture every message.

Is our data used to train AI models?

No. AI is used only where you ask for it - drafting an email, summarising a report section, researching target ideas - and only the text of that request is sent. We do not train models on your data and our providers' business terms prohibit training on it.

Can we get our data out?

Yes, at any time, without asking us. Settings -> Security exports your workspace as structured files: deals, contacts, documents and their download links, drafts, templates, mandate terms and the activity record. There is no exit fee and no notice period.

What happens if DealLaunch stops trading?

Your data is exportable on demand today, which is the only answer that actually protects you. We recommend taking a periodic export and keeping it with your own records, exactly as you would with any vendor.

Is there an audit trail?

Every material change to a deal, contact, document or report writes an append-only activity record with a timestamp and the person who made it, and it is included in your export. A separately hardened, tamper-evident audit log with a dedicated actor field is in progress - see the honest list below.

Do you hold SOC 2 or ISO 27001?

No, and we will not imply otherwise. We are a young company. Our infrastructure providers hold those certifications for the layers they operate; we do not hold one for ours. If a certification is a hard requirement for your firm, tell us before you trial the product.

Is DealLaunch a regulated firm?

No. DealLaunch AI is workflow software. It does not provide investment advice, investor matching, brokerage, placement agency or any regulated financial service, and it must not be relied on as any of those.

Sub-processors

The complete list, published rather than held back for procurement. The full table, with the notification commitment, is on the sub-processors page.

ProcessorPurposeWhat it can see
SupabaseDatabase, authentication and file storageAll workspace data: deals, contacts, activity, uploaded documents
VercelApplication hosting and server functionsData in transit while a page or API call is being served
AnthropicAI drafting and summarising, where you ask for itOnly the text of the specific draft or summary you request. Not used to train models.
OpenAIAI research assistance for target ideas, where you ask for itOnly the brief you submit for that request. Not used to train models.
StripePayment processing, if and when you subscribeBilling details only. No deal data.

What we do not have yet

A reviewer will find these anyway, so here they are first.

  • No SOC 2 Type II or ISO 27001 certification of our own.
  • No formal penetration-test report to share yet.
  • A hardened, tamper-evident audit log with a dedicated actor field and login, export and permission events is in progress.
  • No published uptime SLA. We do not run one for a product at this stage, and we will not pretend to.

Something missing that your firm needs answered? Write to hello@deallaunch.ai and the answer gets added to this page.