Data & Security.
- How is my deal data protected?
Valuenest runs entirely on Amazon Web Services, in U.S. regions. We operate no servers of our own. Physical security, network infrastructure, and hardware controls are inherited from AWS, which holds SOC 1/2/3, ISO 27001, and FedRAMP authorizations.
Everything is encrypted: TLS 1.2+ in transit, AES-256 at rest, keys managed within AWS. Access to production systems follows least-privilege principles, protected by multi-factor authentication, with administrative activity logged. Everyone with potential access to customer data, employees and contractors alike, is bound by written confidentiality obligations. We're deliberately small: the number of people who could ever touch your data is countable on one hand.
- Is my data used to train AI models?
No. Your deal documents are never used to train AI models, not by Valuenest, not by AWS, not by any third-party model provider.
All AI processing runs through Amazon Bedrock, inside our AWS environment. AWS's commitments here are explicit and contractual: Bedrock doesn't store or log model inputs or outputs, and model providers never see your data. Models run in dedicated deployment accounts, and provider access to prompts, documents, or results doesn't exist.
We do use de-identified, aggregated data (never client names, never identifiable figures) to improve our scoring methodologies, benchmarks, and models over time. That's how the Market Readiness Assessment gets sharper without any client's information being visible in it.
- Can other people see my data or analysis?
Not by default. Your deal documents and analysis are visible only to your firm and to Valuenest team members who need access to support your account, all bound by confidentiality obligations. We don't share deal data across customers, and we never sell your data or share it with third parties for marketing.
You can extend access deliberately: your firm can add an Authorized Viewer, permissioned to view a specific report, for anyone who needs it: a seller, a seller's advisor, or a transaction manager, for example.
- Can I delete my data?
Yes. Email privacy@valuenest.ai to request deletion. We'll honor the request within a reasonable period of time, subject to applicable legal retention requirements and our own data retention obligations. Full terms are in our Data Processing Agreement.
- What happens to my data if I stop using Valuenest?
We keep your data until you explicitly deactivate your account, whether through account settings or by contacting us. A quiet stretch on the platform doesn't trigger deletion; deal timelines vary, and a gap in activity doesn't mean you're done. Once your account is deactivated, we delete or return your data per our standard retention policy. The only thing that survives is de-identified, aggregated data that can't be traced back to any client, deal, or business.
- Are you SOC 2 compliant?
Not yet. SOC 2 is on our compliance roadmap. Today, our controls are built on AWS's certified infrastructure and informed by industry security frameworks. Happy to walk your team through our architecture directly, just ask.
- Do you have cyber insurance?
Yes. Valuenest maintains technology errors & omissions and cyber liability insurance.
- What happens if there's a security incident?
Our incident notification and remediation commitments are set out in our Data Processing Agreement and Terms of Service.
- How do I report a security vulnerability?
Email security@valuenest.ai. We investigate all good-faith reports promptly and won't pursue action against researchers acting in good faith.
Questions about anything here? security@valuenest.ai