← Back to GoldDeskIQ

Security & Data Use

Last updated August 19, 2026

Hosting and delivery

GoldDeskIQ runs on the Base44 application platform. Static assets and page requests are delivered through Cloudflare's content delivery network.

Encryption in transit

All traffic is served over HTTPS/TLS, and HTTP Strict Transport Security (HSTS) is enabled so browsers refuse to connect over plain HTTP.

Tenant separation

Each brokerage firm is represented as its own company record, and platform-level access rules restrict records to the firm that owns them. Users see their own firm's data; platform administrators retain access for support and operations.

AI and data handling

AI features — including GOLDIE, brief and document generation, research, and coaching — send the text you supply to the platform's AI model providers in order to produce a response.

Our internal usage analytics record only metadata: which feature was used, when, by which user account, and the title of our own content. They do not store prospect identities, search terms, or conversation text.

Authentication and access

Access requires a user account with an email address and password, and sessions are token-based. Google sign-in is available. Accounts are created by invitation from a firm administrator or the platform team, and each account carries a role that determines what it can reach.

Data retention and deletion

Your data is retained for as long as your firm's subscription is active. When an account is closed, its data is removed according to the hosting platform's deletion process. Firm administrators can delete individual records at any time from within the application.

Reporting a security concern

Email intel@golddeskiq.com with details and steps to reproduce. Our disclosure preferences are published at /.well-known/security.txt.

Your responsibilities

Keep your login credentials confidential and do not share accounts between people.

Ensure any prospect or client information you enter was lawfully obtained and that your outreach complies with the rules that apply to you.

Review every AI-generated document before it reaches a client, and meet the data protection and recordkeeping requirements of your own jurisdiction.

What we do not claim

GoldDeskIQ does not currently hold SOC 2, ISO 27001, HIPAA, or any other third-party security certification, and we make no compliance attestations. This page describes only what we can document today, and we will update it as that changes.

Questions? intel@golddeskiq.com