Gold Sifter processes personal and self-reported financial information, so the way that data is handled is part of the product, not an afterthought. This page states our commitments and how they are enforced. The full technical detail is provided under NDA during diligence and set out in the engagement's data processing terms.
Your investor records live in your own CRM the entire time. Gold Sifter writes into the systems you already operate and never becomes the sole home of your pipeline.
Access to your data is limited to your engagement and to the people and processes that operate it. Sensitive fields are handled on a need-to-use basis, not exposed broadly.
All data moving between your funnel, Gold Sifter, and your CRM travels over encrypted connections (TLS). Credentials and API tokens are stored as managed secrets, never in plaintext.
Your leads and investor data are processed to research, score, and file records for your raise. We do not use your data to train shared or third-party AI models.
Each client's data is isolated to its own tenant. One raise's records, benchmarks, and reports are never visible to another client. Any cross-raise aggregate use is governed by the aggregate-use terms in your agreement.
You receive a clean export of anything Gold Sifter produced at any time. On cancellation, our copy of your data is handled per the retention terms in your agreement, and deleted on request.
Every write Gold Sifter makes to your CRM returns a receipt, and consequential changes are staged for human confirmation rather than made silently, so there is always a record of what changed and when.
Gold Sifter never contacts investors, never makes accreditation determinations, and never touches funds or wire instructions. Those boundaries are part of the design, which limits the sensitivity of what the system does with the data it holds. See the full boundary →
The controls buyers ask about first, stated plainly. Items marked "per engagement" are confirmed in writing during onboarding; NDA is reserved for architecture diagrams and penetration-test material.
| Encryption in transit | TLS on every connection between your funnel, Gold Sifter, and your CRM |
| Encryption at rest | Encrypted storage on operator-managed infrastructure; specifics confirmed in the security review |
| Hosting | Operator-managed infrastructure, US region, fronted by Cloudflare; details per engagement |
| Secrets | Credentials and API tokens stored as managed secrets, never in plaintext |
| Access | Least-privilege, tenant-scoped; operator access is logged |
| Backups | Point-in-time backups before every consequential write; backup and recovery cadence per engagement |
| Retention | Engagement-term retention by default; clean export any time; deletion on request, confirmed in writing |
| Incident response | Direct operator notification without undue delay; process confirmed in the engagement's data terms |
| Model providers | Commercial AI providers under zero-retention business terms; your data never trains shared models |
| Security contact | [email protected], answered by the operator |
For diligence: architecture diagrams, penetration-test material, the subprocessor list, and a data processing addendum are provided under NDA as part of a security review, and the applicable terms are made contractual in the engagement agreement. Ask for the security packet when you are ready to evaluate.