Security and governance.

Deal data is confidential by construction. This page lists what is in place today, what Enterprise terms add, and what is not yet in place — in that order.

In place today

Encrypted in transit and at rest

In place

Uploaded documents are stored in Google Cloud Storage, structured deal state in Cloud SQL for PostgreSQL, and document embeddings in a Qdrant instance on a private network. All three sit in a single United States region. Data is encrypted in transit and at rest with Google-managed keys; customer-managed keys are not offered today.

One workspace, one tenant

In place

Deals, documents, financial snapshots, risks, assumptions, runs, and approvals are all keyed to a company workspace and filtered by it on every read. Claude Code, Claude Cowork, and Codex reach the record through a company-scoped, metered, audited MCP rail with OAuth 2.1 and PKCE, so an agent sees exactly what the person who connected it can see. Multi-fund workspace separation is an Enterprise term.

Not used for learning unless you opt in

In place

Learning-export consent is off by default and is a workspace decision, stamped with who granted it and when. Until a company admin opts in, none of your documents, memos, or agent runs are prepared for learning: the nightly export skips the workspace in its query and again before any upload. When a workspace opts in, its own verified agent runs and analyst corrections are written to a tenant-partitioned dataset in OloLand’s cloud storage, sample and demo deals excluded, so the firm’s own method can be learned. Those datasets are never combined across workspaces, and aggregate model training is unscheduled and fails closed until a purpose-specific, recorded authorization exists. Shared model training and evaluation use public filings and synthetic corpora only. Inference providers run under enterprise terms.

Approvals stay human

In place

IC packages, memo approvals, patches to deal records, and outbound actions pass through explicit human approval steps that live outside the agent rail. An agent can propose a patch or submit a plan; it cannot approve one. This holds regardless of which model produced the work or which surface it ran on.

Every agent run is on the record

In place

Each agent run is written to a durable ledger with the provider and served model that actually answered, the tools it called and their inputs, the citations it returned, and any verifier or grader verdict. Runs can be listed and inspected span by span; runs on OloLand’s own harness can be replayed, while managed-agent runs are provenance-linked to their platform session rather than re-run. Deal-file downloads are logged. A regulator-ready export of a deal record can be requested from the workspace.

SOC 2 Type II — in progress

In progress

A SOC 2 Type II audit is in progress, with continuous control monitoring through Vanta. Live control status is published on the trust center. Until the report is issued, OloLand makes no certification or compliance claim, and contractual language reflects the current state rather than the goal.

Where data lives, where reasoning runs

The record and the reasoning are separate, on purpose. Models are replaceable; the record is not.

The record

Deal state, financial snapshots, assumptions, evidence links, runs, and approvals in PostgreSQL; uploaded documents in Google Cloud Storage; embeddings in Qdrant on a private network. All in one United States region on Google Cloud.

The reasoning

Inference runs on Google Vertex AI (Gemini) and on Anthropic Claude through AWS, under each provider’s enterprise terms. Deterministic engines — DCF, LBO, Monte Carlo, comparables, the forensic battery — run as OloLand services and never inside a model. Which providers process deal text, and under what retention and model-improvement terms, is disclosed during procurement; the Privacy Policy covers OloLand’s own retention and deletion.

The agent surfaces

Claude Code, Claude Cowork, and Codex reach the same record over a company-scoped, metered, audited MCP rail with OAuth 2.1 and PKCE. Ordinary record writes, such as creating a deal or recording an outcome, act as the connected person. Governed judgment actions — patches to deal records, version commits, IC-package approval — fail closed without a human approval.

Enterprise terms

For multi-fund platforms and regulated institutions. Scope and availability of each control are confirmed during procurement, not assumed.

  • SSO / SAML
  • Multi-fund workspace separation
  • VPC deployment option
  • MSA, DPA, and Standard Contractual Clauses
  • Negotiated audit-retention requirements

Not yet in place

Stated here so nobody has to ask. Each item moves to the list above when it ships, not before.

SOC 2 Type II report

The audit is in progress. Until the report is issued, no SOC 2 claim is made in contracts or on this site beyond “in progress”.

Automated retention enforcement

Deleting a deal removes the record and queues deletion of its original uploads, including the archive it arrived in; the purge is asynchronous and best-effort, with failed purges recorded for retry. Deletion requests are honored on request. Scheduled retention policies are not yet enforced automatically; Enterprise contracts can set retention terms that are applied manually.

Customer-managed encryption keys

Encryption at rest uses Google-managed keys. Customer-managed keys are not offered.

Controlled-AI mode

A mode that restricts which models may serve a workspace is roadmap, not a current capability. Confirm required controls during procurement.

Questions

Security questionnaires, DPAs, and Enterprise terms go to sales@ololand.ai. Privacy requests go to privacy@ololand.ai.

Optional analytics

Help us improve the acquisition experience.

With your permission, Google Analytics, Google Ads, Cloudflare, and PostHog measure page visits and conversion paths. PostHog autocapture and session recording stay off. We do not send form contents, uploaded documents, email addresses, or phone numbers in behavioral events. This choice does not enable personalized ads or enhanced-conversion user data. Read our Privacy Policy.