Minimize
Limit collection to the approved entities, fields, date ranges, and hypotheses. The public fit-review form explicitly prohibits contract and transaction uploads.
Commercial agreements and transaction records are sensitive. TermDelta’s diagnostic model is designed around bounded copies, explicit controls, explainable evidence, and customer approval.
No production write access. No website file upload. No silent use of customer data.
Limit collection to the approved entities, fields, date ranges, and hypotheses. The public fit-review form explicitly prohibits contract and transaction uploads.
Use a dedicated engagement workspace and access group. Customer materials are not used for marketing, unrelated analysis, or model training without explicit written permission.
Apply least privilege, named access, multi-factor authentication, and customer-approved transfer methods before receiving sensitive business records.
Preserve source lineage and review state so a finding can be tied to the agreement, logic, affected transactions, calculation, and approver.
Agree retention and deletion terms in writing before transfer. Avoid indefinite copies and document verified deletion at engagement close where required.
No finding becomes a claim, counterparty communication, accounting entry, or success-fee event without customer authorization.
Written scope, data inventory, fields, retention, transfer method, roles, and exclusions.
Customer-approved encrypted channel; no email attachment or public form upload.
Restricted workspace, logged access, normalized working copies, and source lineage.
Customer business owners validate term logic, context, attribution, and disposition.
Deliver agreed outputs and execute the written retention or deletion schedule.
TermDelta publishes assurance language only when the underlying control, vendor, document, and evidence exist.
Not by default. Any model use, provider, retention behavior, and opt-out/control must be documented in the engagement’s security materials. Customer data cannot be reused for unrelated training without explicit written permission.
Yes. The intended starting pattern uses controlled copies of approved exports. If later automation needs credentials, access is scoped, revocable, and separately approved.
No certification is claimed. If a buyer requires specific certification, hosting, residency, pen testing, insurance, or contractual controls, those requirements must be resolved before the engagement.
Only named, authorized personnel and approved service providers required to deliver the engagement, subject to written obligations. The final list must appear in the security brief and subprocessor inventory.
The website collects only qualification details. Data transfer begins after a documented engagement design and appropriate agreements.