Security & data handling

How we handle investor and lead data

Gold Sifter processes personal and self-reported financial information, so the way that data is handled is part of the product, not an afterthought. This page states our commitments and how they are enforced. The full technical detail is provided under NDA during diligence and set out in the engagement's data processing terms.

You own the data

Your investor records live in your own CRM the entire time. Gold Sifter writes into the systems you already operate and never becomes the sole home of your pipeline.

Scoped, least-privilege access

Access to your data is limited to your engagement and to the people and processes that operate it. Sensitive fields are handled on a need-to-use basis, not exposed broadly.

Encrypted in transit

All data moving between your funnel, Gold Sifter, and your CRM travels over encrypted connections (TLS). Credentials and API tokens are stored as managed secrets, never in plaintext.

Your data does not train shared models

Your leads and investor data are processed to research, score, and file records for your raise. We do not use your data to train shared or third-party AI models.

Tenant separation

Each client's data is isolated to its own tenant. One raise's records, benchmarks, and reports are never visible to another client. Any cross-raise aggregate use is governed by the aggregate-use terms in your agreement.

Retention and deletion

You receive a clean export of anything Gold Sifter produced at any time. On cancellation, our copy of your data is handled per the retention terms in your agreement, and deleted on request.

Write receipts and access records

Every write Gold Sifter makes to your CRM returns a receipt, and consequential changes are staged for human confirmation rather than made silently, so there is always a record of what changed and when.

The compliance boundary is built in

Gold Sifter never contacts investors, never makes accreditation determinations, and never touches funds or wire instructions. Those boundaries are part of the design, which limits the sensitivity of what the system does with the data it holds. See the full boundary →

Trust center · baseline controls

The controls buyers ask about first, stated plainly. Items marked "per engagement" are confirmed in writing during onboarding; NDA is reserved for architecture diagrams and penetration-test material.

Encryption in transitTLS on every connection between your funnel, Gold Sifter, and your CRM
Encryption at restEncrypted storage on operator-managed infrastructure; specifics confirmed in the security review
HostingOperator-managed infrastructure, US region, fronted by Cloudflare; details per engagement
SecretsCredentials and API tokens stored as managed secrets, never in plaintext
AccessLeast-privilege, tenant-scoped; operator access is logged
BackupsPoint-in-time backups before every consequential write; backup and recovery cadence per engagement
RetentionEngagement-term retention by default; clean export any time; deletion on request, confirmed in writing
Incident responseDirect operator notification without undue delay; process confirmed in the engagement's data terms
Model providersCommercial AI providers under zero-retention business terms; your data never trains shared models
Security contact[email protected], answered by the operator

For diligence: architecture diagrams, penetration-test material, the subprocessor list, and a data processing addendum are provided under NDA as part of a security review, and the applicable terms are made contractual in the engagement agreement. Ask for the security packet when you are ready to evaluate.