Encrypted in transit and at rest
In placeUploaded documents are stored in Google Cloud Storage, structured deal state in Cloud SQL for PostgreSQL, and document embeddings in a Qdrant instance on a private network. All three sit in a single United States region. Data is encrypted in transit and at rest with Google-managed keys; customer-managed keys are not offered today.
One workspace, one tenant
In placeDeals, documents, financial snapshots, risks, assumptions, runs, and approvals are all keyed to a company workspace and filtered by it on every read. Claude Code, Claude Cowork, and Codex reach the record through a company-scoped, metered, audited MCP rail with OAuth 2.1 and PKCE, so an agent sees exactly what the person who connected it can see. Multi-fund workspace separation is an Enterprise term.
Not used for learning unless you opt in
In placeLearning-export consent is off by default and is a workspace decision, stamped with who granted it and when. Until a company admin opts in, none of your documents, memos, or agent runs are prepared for learning: the nightly export skips the workspace in its query and again before any upload. When a workspace opts in, its own verified agent runs and analyst corrections are written to a tenant-partitioned dataset in OloLand’s cloud storage, sample and demo deals excluded, so the firm’s own method can be learned. Those datasets are never combined across workspaces, and aggregate model training is unscheduled and fails closed until a purpose-specific, recorded authorization exists. Shared model training and evaluation use public filings and synthetic corpora only. Inference providers run under enterprise terms.
Approvals stay human
In placeIC packages, memo approvals, patches to deal records, and outbound actions pass through explicit human approval steps that live outside the agent rail. An agent can propose a patch or submit a plan; it cannot approve one. This holds regardless of which model produced the work or which surface it ran on.
Every agent run is on the record
In placeEach agent run is written to a durable ledger with the provider and served model that actually answered, the tools it called and their inputs, the citations it returned, and any verifier or grader verdict. Runs can be listed and inspected span by span; runs on OloLand’s own harness can be replayed, while managed-agent runs are provenance-linked to their platform session rather than re-run. Deal-file downloads are logged. A regulator-ready export of a deal record can be requested from the workspace.
SOC 2 Type II — in progress
In progressA SOC 2 Type II audit is in progress, with continuous control monitoring through Vanta. Live control status is published on the trust center. Until the report is issued, OloLand makes no certification or compliance claim, and contractual language reflects the current state rather than the goal.