TELOVANT
Request early accessEarly access

Security & trust

How Telovant protects your deal data

What happens to your deal documents, who can see them, and what we do not do yet.

Last updated

We reply within one working day with the DPA, the subprocessor list and answers to your security questionnaire.

The short answers

Hosting
Google Cloud. We can host in a specific region, such as the EU, when a customer needs it.
AI provider
No training on your data. Retention terms are in the DPA.
Pilot data
Deleted 30 days after the pilot, or sooner on request: in the platform or at info@telovant.com
Certifications
None yet. We send the DPA and answer your security questionnaire.

What we commit to

  • Encrypted in transit and at rest
  • Your documents don't train AI models
  • A person approves every extracted item
  • A DPA with every customer

Data protection

How your data is protected

Encrypted in transit and at rest

Traffic to and from Telovant uses TLS. Stored data, including your documents, is encrypted with AES-256 by Google Cloud.

Your documents don't train AI models

Telovant reads documents with general-purpose AI models from third-party providers. We only use providers whose terms say they do not train their models on customer data, and Telovant does not train on it either.

Only invited people can sign in

An admin invites each user. Approvals and admin actions need a second factor, and roles decide who can approve what.

Who processes your data

These subprocessors handle your data for Telovant. The DPA has the full list with names, locations and terms.

Subprocessors
CompanyPurpose
Google CloudHosting, storage and sign‑in
AI model providerReading your documents (named in the DPA)

No security certifications yet

We do not hold SOC 2 or ISO 27001 certification yet. Until we do, we send the DPA with the list of subprocessors and answer your security questionnaire.

Get the DPA and subprocessor list

In the product

Six controls the system enforces

Telovant reports numbers that people are accountable for. These six controls are enforced by the server and the database on every deal.

01

People approve every extracted item

The AI never writes to the record. Every extracted obligation, goal, date and amount goes to a review queue, where a person approves, edits or rejects it. Only committed items are monitored.

In review12
Monitored0
Monitoring starts after a person commits.
02

Every field shows where it came from

Each field in the deal overview shows its source document, section, page and passage, and whether the AI or a person set it. When the overview is rebuilt after a commit, manual changes are kept.

Escrow
€4,800,000MANUAL · j.keller
Replaces AI value €4,750,000 (92%) · SPA §3.4 · p. 14 Changed 2026-04-02 10:12 · kept after every rebuild
03

Waivers need two different approvers

A covenant waiver needs L1 and L2 approval from two different people with the required roles. The person who proposed it can't approve it, and nobody can sign both levels. The server checks this on every decision, whichever app or tool is used.

WV-0007 · approval rules
Proposed by
a.devries
L1 approval
m.osei
L2 approval
a third person with the L2 role
proposer ≠ L1 proposer ≠ L2 L1 ≠ L2 role required per level
04

The audit logs

Every action, from commits and edits to approvals and signed-off measurements, is written to an audit log that only accepts new entries. Each entry contains the hash of the previous one, so the history can be checked from start to end and any change breaks the chain. The full log exports to CSV.

  1. #1040 · waiver.proposedhash 9f3a…c21e
  2. #1041 · waiver.l1_approvedprev 9f3a…c21e · hash 2b77…e04f
  3. #1042 · measurement.attestedprev 2b77…e04f · hash c41d…19a8
05

Measurements are signed off and never edited

Covenant and earnout tests run on measurements that are recorded once and linked to the person who signed them off. A correction is a new measurement, and the old one stays in the record. Pass and fail follow from the threshold and are never typed in.

€2,690,000first reading, corrected
€2,710,000PASSsigned off by j.keller · 2026-07-31
06

Low-confidence results are checked again

Every extraction has a confidence score, shown in three bands: high (85% and up), medium (70 to 85%) and low (under 70%). Below 70%, a stronger model analyses the item again and it is marked as escalated.

94%High: can be approved in bulk
82%Medium: reviewed one by one
61%Low: checked again by a stronger model

Back-test pilot

How your documents are handled in a back-test

About the back-test pilot
DPA before any upload
Signed with every pilot team. It includes the list of subprocessors.
NDA if you want one
Optional. We sign yours or send ours.
Storage and deletion
Stored and deleted as in the short answers at the top of this page.

Security documents

Ask for our security documents

We send the DPA with the list of subprocessors, and we answer your security questionnaire. For questions about architecture, data handling or deployment, email info@telovant.com.

Found a vulnerability? Email security@telovant.com.