Data handling
What data ClosePilot stores, why, and how it supports audit packs.
How we're different
- Evidence-first: each task links to artifacts and approvals.
- Immutable timeline for “who/what/when/why.”
- Exports prioritize audit readiness over dashboards.
Trust rule: AI drafts, humans decide for sensitive outcomes.
Data we may store
- Task metadata (owners, due dates, policy level)
- Evidence request drafts (email/slack text) and timestamps
- Uploaded evidence files (hashes + storage pointers)
- Reconciliation inputs (CSV files) and match outputs
- Approvals and rationale (who approved what)
- Audit log events (append-only)
Retention & deletion (illustrative)
- Configurable retention per tenant
- Legal-hold roadmap for regulated customers
- Export-first: binders remain useful outside ClosePilot
Not legal advice. Final retention policies are your responsibility.
PII handling
- We minimize sensitive fields in logs.
- Access is role-based; sensitive actions are approval-gated.
- Exports can be scoped to a close period and content class.