Security answers,
clearly.
Procurement negotiations include sensitive pricing, terms, and internal constraints. This page summarizes how Negotiations.AI approaches security and what to expect in a security review.
Compliance & privacy
A clear snapshot of our current security and privacy posture for enterprise reviews.
SOC 2 Type II
Negotiations.AI is SOC 2 Type II compliant. Supporting documentation is available via the Trust Center and during your security review (NDA-friendly).
ISO/IEC 27001:2022
Negotiations.AI is ISO/IEC 27001:2022 certified. Supporting documentation is available via the Trust Center and during your security review (NDA-friendly).
GDPR
Negotiations.AI is GDPR compliant. We support data deletion and can share DPA and subprocessor details during your security review.
Trust snapshot
Use the links below for security documentation and our GDPR trust portal.
Representative
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
- United Kingdom (UK)
- Switzerland
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website:
https://app.prighter.com/portal/17373130481At a glance
The most common questions we get from security, legal, and procurement leadership.
Access controls and governance
Workspaces are organization-scoped with role-based access and audit-friendly workflows (approvals, audit log, and retention policies).
Private content is not for training
We do not use your private negotiation content to train public models.
Security review ready
We support security questionnaires and share architecture and processing details during your review (NDA-friendly).
You control your data lifecycle
You can delete your data at any time. We can also align retention to your governance requirements.
What your security team cares about
Your team needs to know where sensitive files go, who can access them, and how AI processing is controlled.
Security review checklist
- Data flow (ingest → processing → outputs → retention/deletion)
- Subprocessors and model provider handling (NDA-friendly)
- Access control model (RBAC, org isolation, SSO/SAML for enterprise)
- Auditability (approval trails, audit logs, retention policies)
Security FAQ
Need a fast security review?
Send your questionnaire or required controls list and we’ll respond with documentation and a walkthrough.