Security & Trust

Institutional underwriting deserves institutional security.

Your pipeline, your assumptions, and your returns are competitively sensitive. Here is exactly how MultiScreen protects them, in plain English, with no certifications we haven't earned.

Your deal data stays yours

  • Every deal is private to your account. No other account can see your deals, your documents, or your assumptions, and we never sell or share your data with brokers, lenders, data vendors, or anyone else. Your underwriting is your edge, we treat it that way.
  • One feature, Underwriter Consensus, shows the median and range of what other MultiScreen users assumed for a market this quarter (exit cap, rent growth, and similar), so you can see where your number sits. It is built only from anonymized aggregates: no deal, no dollar figure, and no individual's inputs are ever shown, each underwriter counts once regardless of how many deals they have, and a market publishes nothing until at least 18 separate underwriters have deals there, so nobody can be singled out. You can remove your deals from these anonymous pools at any time from the Leaderboard page in the app.
  • The underwriting engine runs entirely server-side. Your browser sends assumptions and receives results; the formulas and your competitors never meet your numbers.

AI that never trains on your deals

  • AI features (document import, IC memo drafting) run on the Anthropic API. Under the API terms we operate on, inputs and outputs are not used to train Anthropic's models.
  • AI writes prose only, every number in every output comes from the deterministic engine, never from a language model.

Built on SOC 2-certified infrastructure

  • Authentication: Clerk (SOC 2 Type II), passwords and sessions never touch our servers. Multi-factor authentication is available on every account.
  • Payments: Stripe (PCI DSS Level 1), we never see or store your card number.
  • Hosting and database: Vercel and managed Postgres (SOC 2), with data encrypted in transit (TLS 1.2+) and at rest (AES-256).

Operational safeguards

  • API rate limiting protects the service against abuse and scraping.
  • Pro features and usage caps are enforced server-side on every request, not just hidden in the interface.
  • Want your data exported or deleted? Email hello@multiscreen.co and we'll handle it promptly.

Questions about security, or need a vendor questionnaire completed? Email hello@multiscreen.co.