Security and privacy

Where your documents live, who can read them, and what is ever shared

This page states what the system actually does, in the order investors usually ask.

Documents are private storage, read only through authentication

Every uploaded file lives in a private store. Reading a file requires an authenticated request with a store credential; there is no such thing as a public link to a document, and a URL copied out of the system returns an authorization error, not a file. The one place a document can be opened in a browser is by its owner, through a route that checks on every request that the signed-in account owns the deal the file belongs to.

Your workspace is isolated

Every read of a deal, its documents, its analysis, and its chat is scoped to the account that created it. Other evaluators cannot open your deals, see your documents, or read your analysis, and you cannot open theirs. This holds even when two evaluators analyze the same real-world deal: the deal's identity is shared, the records never are.

Share links carry the analysis, never the files

A share link renders the report: scores, flags, benchmarks, answered and open questions. It has no access to documents, because the page it renders never touches them. The same is true of the sponsor workspace: a sponsor sees the report and the open questions, never the files, and never who is evaluating.

What Discover shows

Deals raising publicly under Rule 506(c) appear named on Discover, because the raise is already public in the sponsor's own advertising and SEC filing. What appears is summary data: category, headline terms, a rating, evaluator count. Evaluator identities never appear anywhere, documents are never reachable, and any owner can hide their deal from Discover with one click on its page. Deals not raising publicly appear only as anonymized summaries, unnamed.

Benchmarks cannot leak a single deal's terms

Category benchmarks are computed across deals, and a row is shown only when at least three distinct deals stand behind it, for everyone, signed in or out. Percentile placement on a report requires at least five. Below those floors the system shows nothing, so no benchmark can ever be reverse-engineered into one deal's fee or promote.

Deletion means deletion

Deleting a deal removes its analysis and deletes its files from the private store. It is not a soft hide. There is also a stronger option per deal: purge the source files while keeping the structured record, after which Argus no longer holds the documents at all. The trade is stated at the moment of purging: the analysis and score remain, but the files cannot be re-read.

Model processing

Documents are processed by a frontier model over an API on commercial terms under which the provider does not train on the data. Extraction output, the structured record the reports are built from, is stored; it lives under the same per-account isolation as everything else.

Questions this page does not answer are welcome: the methodology page has a contact form that reaches a person.