Security & trust

Trust comes
from architecture.

Goldstone is early-stage. What we have is a system designed honestly — with explicit rules about what it does, what it never does, and how your data is handled.

01

Your data is yours.

Your Vault belongs to you. Export the entire structure as JSON or CSV at any time. Delete your account and we remove the data within thirty days. We do not sell data, and Vault content is never used to train shared models.

02

You initiate every outside action.

Goldstone never submits an application on your behalf. We never send outbound email or contact a funder without your explicit action. There is no auto-submit, and the final click is always yours.

03

AI is constrained.

Where AI is used — for optional document polish — it is bounded by prompt to not change meaning, add sections, or invent facts. If no API key is configured, the AI step is silently skipped and your document is the deterministic Vault-merge.

04

Matching is explainable.

Every match score breaks down into per-component reasons you can read — region, industry, stage, check-size — with disqualifiers explicit. There is no black box and no learned model in the scoring path.

05

Sources are official.

Funding opportunities come from official government and program sources. Listings are normalized and deduplicated. Amount and deadline are parsed by regex, not guessed.

06

Encrypted, audited, versioned.

Vault data is encrypted at rest and in transit. Access to production data is restricted and logged. Vault edits and document drafts are versioned and timestamped — you can restore any prior state.

What we never do

The list of things
we will not do.

  • — We do not sell or share your Vault data.
  • — We do not train models on your inputs.
  • — We do not auto-submit to funder portals.
  • — We do not invent facts in your documents.
  • — We do not fabricate match scores.
  • — We do not lock you in. Export is one click.
Verified by design

Trust the system.