Home About Who We Are Team Services Startups Businesses Enterprise Case Studies Industries Commercial Real Estate Blog Guides Contact Connect with Us
All Commercial Real Estate guides
Real Estate 15 min read

How to Evaluate Whether an AI Tool Is Safe for Confidential Deal Data

How to Evaluate Whether an AI Tool Is Safe for Confidential Deal Data

An AI tool is safe for confidential deal data when three things are true: it does not use your inputs to train its models, it retains what you give it only briefly and lets you delete it, and you know exactly which company’s servers see the document. Everything else — the certifications, the security page, the sales rep’s assurances — either supports those three facts or distracts from them. You do not need an IT department to check them. You need about an afternoon and the five questions below, ordered from the exposure most firms already have to the ones a vendor will point you toward.

Deal data is not generic “business data.” It is a seller’s unpublished financials under an NDA, a rent roll that names every tenant and their rate, a buyer’s identity and maximum price, offer terms you are contractually bound to keep quiet. A leak here is not a compliance ticket; it is a broken confidentiality agreement, a fiduciary lapse, and a seller who never calls you again. That is why the safety question deserves a real answer rather than a shrug, and why the discipline of using AI without exposing the very information that makes you valuable is part of how a small firm out-operates much larger competitors instead of handing them an edge.

What “Confidential Deal Data” Actually Means

Sort your information into two buckets before you evaluate any tool. The first is public or low-sensitivity: a listing flyer, a market rent comp, a property address. The second is confidential: anything covered by an NDA, anything a counterparty gave you in confidence, anything that would embarrass a client or move a price if it got out.

The safety bar is set by the second bucket. A tool that is fine for drafting a listing description is not automatically fine for summarizing a seller’s private operating statement. When you evaluate, test the tool against the confidential bucket, because that is the data that carries real consequences if the tool mishandles it.

Start With the Account You Already Use

The biggest exposure in most small firms is not a tool they are considering; it is the one they already opened. Someone on the team has been pasting deal memos, LOIs, and offering memoranda into a free or personal ChatGPT account for months, because it works and nobody told them not to.

That matters because consumer AI accounts and business accounts have different defaults. On consumer plans (the free tier and personal paid tiers of ChatGPT, for example), your conversations may be used to train the provider’s models unless you actively turn that setting off. On the business and enterprise tiers of the major providers — ChatGPT Enterprise and Team, the Claude for Work plans, Microsoft Copilot’s commercial tier — the provider does not use your inputs for training by default.

So the first move is not procurement. It is switching the account your team already relies on from a consumer tier to a business tier, or at minimum turning off training in the settings of the consumer account. This single change closes the most common leak before you evaluate a single new vendor. It is also the change that makes it safe to let AI absorb the grunt work, the reconciling and summarizing that used to define the 60-hour junior-analyst week, without that work quietly feeding a public model.

The Two Questions That Decide Safety

Two questions carry almost all the weight. Get clean answers to both and you have evaluated the substance; everything else is supporting detail.

Does It Train on Your Inputs

Ask the vendor directly: “Do you use our inputs or outputs to train or improve your models, by default?” The answer you want is no, in writing, in the terms, not “we take privacy seriously” on a marketing page.

For the two most common underlying providers, the current commercial answer is no by default. OpenAI does not train on ChatGPT Enterprise, Team, or API inputs and outputs. Anthropic does not train on commercial Claude inputs under its business terms. Verify the current wording yourself at evaluation time, because these policies get revised and a summary you read last year may be stale.

How Long Does It Keep Them, and Can You Delete Them

A tool that does not train on your data can still store it. Ask two things: how long is my data retained, and can I delete it on demand. The major providers retain business-tier data for a limited window (often around 30 days for abuse monitoring) and then delete it; some offer a zero-retention arrangement for eligible customers through a commercial agreement rather than a self-serve toggle.

Retention is not automatically a red flag; a short, disclosed window with a deletion control is normal and fine. An open-ended “we keep it as long as we need to,” or no ability to delete a document you uploaded by mistake, is the problem. You want a stated number and a delete button.

Separate the Tool From the Model Behind It

Most proptech AI features do not run on the vendor’s own model. Tools like Buildout or Dealpath add AI capabilities by calling a foundation model from OpenAI, Anthropic, or Google, which does the actual reading and writing. That means your confidential document can pass through two companies, and both sets of terms have to clear.

This is the same app-versus-engine split that separates a purpose-built tool from the general-purpose model underneath it — the distinction covered in plain terms in our explainer on machine learning versus generative AI for real estate. For safety, the practical consequence is one extra question for any proptech vendor: “Which model provider processes our documents, and does your contract with them prohibit training on our data?” A vendor who cannot answer which company’s servers see your rent roll has not earned a confidential document yet.

What SOC 2, a DPA, and Encryption Actually Tell You

The security page will list acronyms. Here is what the three that matter actually mean for deal confidentiality, in the order a small firm should weigh them.

  • A DPA (Data Processing Agreement) is the contract term that puts the training-and-retention promises in writing rather than on a webpage. Ask for it. This is the single most useful document, because it is enforceable.
  • SOC 2 Type 2 is an independent audit confirming the vendor’s security controls actually held over a period, usually 6 to 12 months. It signals operational maturity. Ask for the report and glance at the observation window. A current one is reassuring; a certification the vendor “is working toward” is not the same thing.
  • Encryption — data encrypted in transit and at rest — is table stakes now offered by every serious vendor. Its absence is disqualifying; its presence is not a differentiator. Note that “encrypted” is not the same as “end-to-end encrypted,” and most AI chat is not the latter, which is why the training and retention answers matter more than the encryption checkbox.

Two more are worth a line each: data residency (can the vendor keep processing in the US, which some clients or partners require) and sub-processors (the list of other companies the vendor shares data with — the model provider will be on it). You do not need to audit these like a procurement officer. You need to confirm they exist and read the two or three lines that touch confidential data.

The Five-Question Safety Test

Run these five questions on any tool before it touches a confidential document. They are ordered from the exposure you probably already have to the ones a vendor will surface for you. Any “no” or “won’t say” on the first three is a stop.

# Question Safe answer Why it matters
1 Is this a business tier, not a consumer account? Business/enterprise tier, or training turned off Consumer tiers may train on your inputs by default
2 Do you train on our inputs or outputs? No, by default, stated in the terms Training means your deal data can surface elsewhere
3 How long is data retained, and can we delete it? A stated window plus a delete control Open-ended storage with no deletion is the real risk
4 Which model provider processes our documents? A named provider whose contract bars training The tool and the model behind it are two separate risks
5 Can you share a DPA and current SOC 2 report? Yes to both Puts the promises in an enforceable, audited form

A tool that clears all five is safe for confidential deal data in the sense that matters: your inputs are not becoming training data, they are not sitting on a server forever, and you know who touches them. A tool that clears the first three but not the last two may still be fine for lower-sensitivity work while you press for the paperwork.

The Go/No-Go Rule for Any Document

Keep one rule at the point of use, because the evaluation above happens once but the decision to paste a document happens every day. If you could not email the document to an outside party without an NDA, it does not go into any tool whose terms you have not cleared.

That rule is simple enough to teach the whole team in a sentence, which is the point — safety fails at the individual keystroke, not in the vendor contract. Making it reflexive across a firm is exactly what a short, practical training effort is for, and it is a core habit in the 90-day plan for making a small firm genuinely fluent with AI. The goal is not to keep confidential data away from AI entirely. Handled on a business tier that does not train on your inputs, AI reading a seller’s financials is no riskier than the analyst who reads them today, a point worth holding onto amid the noise about whether these tools replace brokers or simply do the reading faster. The goal is to decide, deliberately, which tools have earned that trust.

Frequently Asked Questions

Is it safe to put confidential deal data into ChatGPT?

It depends entirely on which account you use. On a consumer plan (free or personal paid), your inputs may be used to train the model unless you turn training off in settings, so it is not safe for confidential deal data as-is. On a business or enterprise tier, OpenAI does not train on your inputs by default and offers a data-processing agreement, which makes it appropriate for confidential work. The single most important step is confirming you are on a business tier, or that training is switched off, before pasting anything an NDA covers.

What does it mean for an AI tool to “train on” my data?

It means your inputs can be absorbed into the model’s future versions, where fragments could surface in answers given to other users. For deal data, that is the core fear: a seller’s private numbers or a buyer’s ceiling becoming, in effect, part of a shared system you no longer control. Business and enterprise tiers of the major providers do not train on your inputs by default, which is why the tier you choose is the first safety decision. Always confirm the “no training” promise is in the written terms, not just on a marketing page.

How can a small firm evaluate AI safety without an IT department?

Run the five-question test: confirm a business tier, confirm no training on your inputs, confirm a retention window with a delete control, identify the model provider behind the tool, and ask for a DPA and SOC 2 report. None of that requires technical skill — it requires asking direct questions and reading the two or three lines of the terms that touch confidential data. A principal can complete the evaluation in an afternoon. The one thing to insist on is written answers rather than verbal reassurance.

What is the difference between the AI tool and the model behind it?

The tool is the application you log into; the model is the underlying engine that reads and writes. Most proptech AI products are an interface built on a foundation model from OpenAI, Anthropic, or Google, so your document passes through two companies and both sets of terms apply. The practical consequence is one extra question: which model provider processes our data, and does the tool’s contract with them prohibit training on it. A vendor who cannot name the provider behind their product has not earned a confidential document.

Does SOC 2 certification mean a tool is safe for confidential data?

SOC 2 Type 2 is a strong signal but not a complete answer. It confirms an independent auditor verified the vendor’s security controls held over a period, usually 6 to 12 months, which speaks to operational maturity. It does not by itself tell you whether the vendor trains on your inputs or how long they retain your data — those live in the terms and the DPA. Treat SOC 2 as necessary evidence of seriousness, then still ask the training and retention questions directly.

What is a DPA and why does it matter for deal data?

A DPA, or data processing agreement, is the contract that puts a vendor’s privacy promises into enforceable language. It is where the “we do not train on your data” and “we retain it for 30 days then delete it” commitments become binding rather than marketing copy. For confidential deal data, the DPA is the single most valuable document to request, because it is the version of the promise you could actually hold a vendor to. A vendor unwilling to provide one for business-tier use is telling you something.

How long do AI providers keep my data?

Business-tier providers typically retain inputs for a limited, disclosed window — often around 30 days for abuse monitoring — and then delete them, with some offering a zero-retention arrangement through a commercial agreement. A short, stated window with a deletion control is normal and acceptable. The warning sign is open-ended retention with no way to delete a document you uploaded by mistake. Ask for the specific number and confirm a delete control exists before trusting a tool with confidential files.

Should I use a general AI tool or a real-estate-specific one for confidential work?

Safety depends on the terms, not on whether the tool is CRE-specific. A general business-tier assistant with clear no-training terms can be safer than a niche proptech tool whose data terms are vague or whose underlying model provider is undisclosed. Judge each option on the same five questions rather than assuming an industry label implies better privacy. Often a general business-tier account is the safe starting point while you evaluate specialized tools against the same bar.

What is the simplest rule my team can follow every day?

If you could not send the document to an outside party without an NDA, it does not go into any tool whose terms you have not cleared. That one sentence covers the daily decision that vendor contracts cannot: the moment someone is about to paste a file. It keeps confidential material out of unvetted tools while still allowing AI on the work you have approved. Pair it with a short list of the specific tools your firm has cleared, so the safe path is also the easy one.

Where to Start

The fastest way to close your real exposure is to look at what your team already uses, not what you might buy. Most firms discover that the first fix is free: move the account people already paste deal memos into onto a business tier, or turn off training, and the largest leak is gone before any procurement begins.

A free AI-readiness assessment does exactly that groundwork with you — it maps which tools your team already touches confidential data with, flags the accounts sitting on the wrong tier, and hands you a short list of what has cleared the safety bar and what has not, in plain language and with no IT department required. Book a free AI-readiness assessment if you want that map before you trust another tool with a seller’s numbers. You will leave knowing which of your current habits are safe, which need a five-minute settings change, and which tools have actually earned your confidential data.

Last Updated: Aug 17, 2026

DJ

Dirk Jan van Veen, PhD

SFAI Labs helps companies build AI-powered products that work. We focus on practical solutions, not hype.

Make your firm fluent in AI — then automate what works

  • Hands-on training applied to LOIs, lease summaries, and market write-ups
  • Automation across documents, deals, communications, and back office
  • Built for 4–20-person firms with no IT department

Related articles