Encrypted in transit and at rest
Traffic to and from Telovant uses TLS. Stored data, including your documents, is encrypted with AES-256 by Google Cloud.
Security & trust
What happens to your deal documents, who can see them, and what we do not do yet.
Last updated
We reply within one working day with the DPA, the subprocessor list and answers to your security questionnaire.
Data protection
Traffic to and from Telovant uses TLS. Stored data, including your documents, is encrypted with AES-256 by Google Cloud.
Telovant reads documents with general-purpose AI models from third-party providers. We only use providers whose terms say they do not train their models on customer data, and Telovant does not train on it either.
An admin invites each user. Approvals and admin actions need a second factor, and roles decide who can approve what.
These subprocessors handle your data for Telovant. The DPA has the full list with names, locations and terms.
| Company | Purpose |
|---|---|
| Google Cloud | Hosting, storage and sign‑in |
| AI model provider | Reading your documents (named in the DPA) |
We do not hold SOC 2 or ISO 27001 certification yet. Until we do, we send the DPA with the list of subprocessors and answer your security questionnaire.
Get the DPA and subprocessor listIn the product
Telovant reports numbers that people are accountable for. These six controls are enforced by the server and the database on every deal.
The AI never writes to the record. Every extracted obligation, goal, date and amount goes to a review queue, where a person approves, edits or rejects it. Only committed items are monitored.
Each field in the deal overview shows its source document, section, page and passage, and whether the AI or a person set it. When the overview is rebuilt after a commit, manual changes are kept.
A covenant waiver needs L1 and L2 approval from two different people with the required roles. The person who proposed it can't approve it, and nobody can sign both levels. The server checks this on every decision, whichever app or tool is used.
Every action, from commits and edits to approvals and signed-off measurements, is written to an audit log that only accepts new entries. Each entry contains the hash of the previous one, so the history can be checked from start to end and any change breaks the chain. The full log exports to CSV.
Covenant and earnout tests run on measurements that are recorded once and linked to the person who signed them off. A correction is a new measurement, and the old one stays in the record. Pass and fail follow from the threshold and are never typed in.
Every extraction has a confidence score, shown in three bands: high (85% and up), medium (70 to 85%) and low (under 70%). Below 70%, a stronger model analyses the item again and it is marked as escalated.
Security documents
We send the DPA with the list of subprocessors, and we answer your security questionnaire. For questions about architecture, data handling or deployment, email info@telovant.com.
Found a vulnerability? Email security@telovant.com.