Security & data handling

Trust starts before the first file moves.

Commercial agreements and transaction records are sensitive. TermDelta’s diagnostic model is designed around bounded copies, explicit controls, explainable evidence, and customer approval.

DEFAULT POSTURERead-only. Minimal. Revocable.

No production write access. No website file upload. No silent use of customer data.

Control principles

Make the data flow smaller, clearer, and easier to stop.

01

Minimize

Limit collection to the approved entities, fields, date ranges, and hypotheses. The public fit-review form explicitly prohibits contract and transaction uploads.

02

Separate

Use a dedicated engagement workspace and access group. Customer materials are not used for marketing, unrelated analysis, or model training without explicit written permission.

03

Restrict

Apply least privilege, named access, multi-factor authentication, and customer-approved transfer methods before receiving sensitive business records.

04

Trace

Preserve source lineage and review state so a finding can be tied to the agreement, logic, affected transactions, calculation, and approver.

05

Retain intentionally

Agree retention and deletion terms in writing before transfer. Avoid indefinite copies and document verified deletion at engagement close where required.

06

Approve

No finding becomes a claim, counterparty communication, accounting entry, or success-fee event without customer authorization.

Diagnostic data flow

Five checkpoints. No ambiguity about custody.

  1. 01
    Approve

    Written scope, data inventory, fields, retention, transfer method, roles, and exclusions.

  2. 02
    Transfer

    Customer-approved encrypted channel; no email attachment or public form upload.

  3. 03
    Analyze

    Restricted workspace, logged access, normalized working copies, and source lineage.

  4. 04
    Review

    Customer business owners validate term logic, context, attribution, and disposition.

  5. 05
    Return / delete

    Deliver agreed outputs and execute the written retention or deletion schedule.

Assurance status

Claims will never run ahead of completed controls.

TermDelta publishes assurance language only when the underlying control, vendor, document, and evidence exist.

Diagnostic security briefPrepared for review
Data processing addendumRequired before data
Subprocessor inventoryRequired before data
Incident response procedureRequired before data
Cyber / E&O insuranceEvaluate before contract
SOC 2 / ISO certificationNot claimed
Security review

Questions buyers can ask immediately.

Does TermDelta train models on customer data?

Not by default. Any model use, provider, retention behavior, and opt-out/control must be documented in the engagement’s security materials. Customer data cannot be reused for unrelated training without explicit written permission.

Can the diagnostic run without production credentials?

Yes. The intended starting pattern uses controlled copies of approved exports. If later automation needs credentials, access is scoped, revocable, and separately approved.

Is TermDelta SOC 2 certified?

No certification is claimed. If a buyer requires specific certification, hosting, residency, pen testing, insurance, or contractual controls, those requirements must be resolved before the engagement.

Who may see our data?

Only named, authorized personnel and approved service providers required to deliver the engagement, subject to written obligations. The final list must appear in the security brief and subprocessor inventory.

Security before sales pressure

Bring security and legal into the scope before sensitive data arrives.

The website collects only qualification details. Data transfer begins after a documented engagement design and appropriate agreements.

Request a confidential fit review