Security

Introduction

DealCraft handles information you wouldn't want anyone else to see: live deal detail, buyer intelligence, and your own commercial positioning. We take that seriously, which is why this page doesn't deal in the vague reassurances. Below is exactly what's isolated, what's encrypted, what's deleted and when, and where a process is still manual rather than automated. If something changes, we'll update this page (date last updated 21 September 2026).

The platform

Each organisation's data is kept separate from every other tenant, and that separation is enforced by the server rather than left to configuration. Access is controlled by role, seller, manager, admin and owner, each checked server-side. You can sign in with single sign-on through Microsoft or Google, or by email with a one-time code; where a password is used, it's hashed with Argon2id. Sessions end automatically after 8 hours of inactivity or 7 days at the most, and you can sign out of every session at once from any device. CRM credentials are stored as encrypted tokens, never in plain text. Standard browser security headers are applied throughout to guard against injected scripts and clickjacking.

Data lifecycle

By default, we don't keep your prompts and responses in our logs. Imported emails are deleted on a set schedule, and expired sign-in data is cleared out every day. At the moment, deletion requests are handled manually rather than through a self-service tool.

AI model security

DealCraft runs on an an open-weights model hosted by Fireworks, so nothing you send is passed on to the model's original developer. Fireworks doesn't log or store prompts or outputs, with one exception: a few minutes of temporary memory used for caching. Fireworks, our AI infrastructure provider, holds a SOC 2 Type II report. DealCraft doesn't fine-tune any model on customer data. Pasted emails and documents are always treated as untrusted content, so instructions hidden inside them can't hijack the AI's behaviour.

If you would like more information about our security then please contact us and we’ll be happy to answer your questions.