Help

Security & privacy

How we protect your data, our AI data policies, and compliance information

We built Deliverables AI for teams that work with confidential deal materials, financial data, and sensitive client information. Security isn't an afterthought — it's foundational to everything we do.

Data encryption

All data is encrypted at every stage:

Layer Standard
In transit TLS 1.3 — all data moving between your browser and our servers is encrypted
At rest AES-256 — all stored data is encrypted on disk

This applies to your uploaded sources, generated deliverables, prompts, and any other data in your workspace.

How your data is used with AI

We never use your data to train AI models. This is a firm policy, not a setting you need to toggle.

  • Your documents, prompts, and generated content are excluded from model training under the commercial terms we operate under with our AI provider (Anthropic)
  • We do not share your data with AI providers for training purposes
  • Retention at the AI provider is policy-bound, not zero. Anthropic automatically deletes standard API inputs and outputs within 30 days under its published retention policy, with the narrow exceptions that policy states (trust-and-safety and legal holds)
  • Tasks run as durable agent sessions — persistent resources that hold conversation state so your work can resume — and that session state is retained at the provider until it is deleted, not on a fixed clock
  • For removal beyond the in-app controls — a whole workspace, or the stored state behind past tasks, on our side or the provider's — email support@deliverables.ai or use the contact form. These requests are handled directly by our team, which will confirm what is removed and when. See Data retention and deletion below for what you can remove yourself

Workspace isolation

Your workspace is completely isolated from other customers:

  • Separate storage — Your files and generated deliverables are stored independently from other workspaces
  • No cross-contamination — One customer's data never appears in another customer's output
  • Independent processing — Your AI generations run in isolated contexts

Access controls

You control exactly who can see your data:

  • Workspace members only — Only users you explicitly invite can access your projects, sources, and deliverables
  • Sharing is opt-in and scoped — A task stays private until you generate a share link for it; that link is a read-only view of that task's title and conversation, accessible to anyone who has the URL with no sign-in required. Nothing else in your workspace is exposed this way, and you can revoke a link at any time, which immediately stops the URL from resolving
  • Support access by permission — Our support team can only access your data with your explicit permission when troubleshooting issues

Data retention and deletion

Your data remains in your workspace for as long as your account is active. What you can remove yourself, and what we handle for you, splits cleanly:

Self-serve, from inside the app

  • Remove individual sources from a project's Sources list
  • Delete projects and tasks you no longer need
  • Deleted data is permanently removed from our systems within 30 days. This covers data we hold; state held at our AI provider is governed by the policies described above and by direct data-removal requests

Handled by our team — email support@deliverables.ai or contact us, and we'll confirm what is removed and when

  • Deleting an entire workspace
  • Exporting your data before you leave
  • Removing the session state behind past tasks

Connectors are opt-in

Deliverables AI does connect to outside systems — Slack, Google Drive, a CRM, a meeting-notes tool, and others — but only the ones you deliberately enable. Nothing is connected by default. Until a connector is turned on for your workspace, the agent has no access to that system, and a connected tool can be disconnected at any time.

Data rooms and VDRs are not connectable today — a Datasite connector is tagged soon in the panel but isn't live yet. Until it is, sensitive deal repositories stay a manual step: you download the files and upload them, rather than the agent reaching in and pulling them.

Whether it's a connector or a direct upload, you decide what enters the system: drag and drop files, paste text, add links, or enable the connectors you need. When you're done, your data stays in your isolated workspace and nowhere else. Learn more about adding sources → | How Deliverables fits in your workflow → | How our security compares to other tools →

Contractual protections

These security practices aren't just policies — they're backed by our Terms of Service. Our agreement includes formal confidentiality obligations with legal protections, meaning your data is covered by enforceable contractual commitments, not just good intentions.

Compliance

We use enterprise-grade cloud infrastructure and are actively pursuing SOC 2 compliance. Our security practices include:

  • Regular security assessments and penetration testing
  • Automated vulnerability scanning
  • Secure development practices with code review
  • Incident response procedures

Audit trail

The credit usage log provides a detailed record of all AI activity in your workspace — what was generated, when, by whom, and at what cost. Teams with internal compliance requirements can use this as a lightweight audit trail for AI-assisted work product.

Have security questions?

We're happy to discuss our security practices in detail with your compliance or IT team. Book a call to go through your specific security requirements, request documentation, or discuss enterprise-grade configurations.

Next steps

    Security & privacy | Deliverables AI Help