Trust & compliance

Built to be audited.

Public sources in, cited and tamper-evident verdicts out. Here's exactly how we handle your data, our compliance posture, and the proof behind it.

Hash-chained audit trail on every run.

Compliance posture

Honest about status

What is implemented today, what is a stated design posture, and what is still in progress. We never imply a certification is complete.

  • Tamper-evident audit

    Implemented

    Tamper-evident, hash-chained audit trail on every assessment.

    Every diligence run writes an append-only, hash-chained audit record. Each entry references the cryptographic hash of the prior entry, so any retroactive edit breaks the chain and is detectable. Citations, inputs, scorer versions, and outputs are all captured in the chain.

    How the audit chain works →
  • Encryption

    Posture

    Public sources in — encrypted in transit and at rest.

    The engine runs on public registries, filings, and web sources, so no sensitive personal records are required to produce a verdict. All customer data in transit is encrypted (TLS) and storage is encrypted at rest (AES-256). This is a stated posture, not a third-party attestation.

  • GDPR

    Posture

    Data-minimisation by design; EU data-handling alignment.

    We follow data-minimisation principles: only the inputs needed to run the diligence scorers are processed, and outputs cite public sources. Data-subject and processing terms are addressed contractually. This reflects our design posture and DPA commitments, not a supervisory-authority certification.

  • SOC 2 Type II

    In progress

    Audit underway — report not yet issued.

    We are actively pursuing a SOC 2 Type II examination. Controls are being implemented and evidenced; the independent report has not yet been issued. We will publish the report status here when available. We do not claim SOC 2 compliance today.

Data handling

Your inputs stay yours

Three commitments that govern how your inputs are processed.

We never train on your data

The companies and founders you submit are not used to train or fine-tune any model.

Self-hosted LLM fleet

Entity resolution runs on our own Qwen models inside our tenant; your queries are never sent to a third-party model provider.

Per-tenant isolation

Your runs, citations, and audit chain are isolated to your tenant.

Provenance & audit

Every number is a citation. Every verdict is hash-chained.

Each diligence verdict cites the source behind every finding, then is hashed into a tamper-evident chain you can export and replay. Any retroactive edit breaks the chain and is detectable.

Sample verdictillustrative — not real data

ENDO-2b · Endometriosis Phase 2b

Feasibility verdict · every number cited

CONDITIONAL GO
PTRS
58%opentargetsClick to inspect & verify ▸
Eligible cohort (US)
24,300aactClick to inspect & verify ▸
Median enrollment
14.2 moclinicaltrialsClick to inspect & verify ▸
Est. per-site budget
$1.18MpubmedClick to inspect & verify ▸
Part 11 tamper-evident · hash e7a1…9f

Every verdict is hashed into a tamper-evident chain you can export and replay.

Data sources

Powered by public data

Every cited number traces back to one of these public, stewarded sources — no proprietary black boxes.

Sources

Built on public data sources

Public, re-verifiable sources — click any finding to check it yourself. Your subjects are never used to train a model.

SEC EDGARU.S. Securities & Exchange Commission
Companies HouseUK Companies House
OpenCorporatesOpenCorporates / GLEIF
OFAC & global sanctionsUS Treasury · EU · UN · UK OFSI
CourtListenerFree Law Project
GDELTThe GDELT Project
USPTOU.S. Patent & Trademark Office

MarketPrior, Inc.

Delaware, United States

Decision-support only — not investment advice or a consumer report.