The audit trail your compliance team will ask for
In regulated buying — the deals that cross pharma, manufacturing, construction, finance — “we agreed” isn't enough. Someone will eventually ask you to prove what was promised and that the customer confirmed it. ValueRoom keeps that proof as an immutable, identity-graded record, built up one customer confirmation at a time.

What the record is
Confirmed by the customer, not claimed by you
Every milestone and outcome in the record was co-signed by the customer — their click, on their side of the room. When someone asks you to prove what was promised and that the customer agreed, you're not reconstructing an email thread; you're showing their own confirmations.
Identity-graded, honestly
Each confirmation records how the person was authenticated when they made it — secure-link possession by default, with an emailed one-time code available as a step-up your team can require before a confirmation counts. The grade is stored on the confirmation itself, so the record says exactly how strong each signature is — no more, no less.
Append-only — at the database
Once a confirmation is recorded, it cannot be edited or deleted — not by an admin, not by us in the normal course of operation. The database itself blocks changes to the attestation record and its audit trail. That's not a retention policy or a permission setting; it's a constraint enforced below the application.
Exportable, raw
The full record exports as raw, machine-readable data — the complete trail, ready to hand to procurement, compliance, or an auditor's tooling. It's your evidence, in a form you can take with you.
The controls your IT team will ask about
Team-side identity and access run on the Atlas plan; the record's guarantees above hold on every plan. Full detail on the plan comparison.
SSO for your team (SAML & OIDC)
Your reps and CSMs sign in through your identity provider.
SCIM directory sync
Seats provision and deprovision from your directory.
Role management (RBAC)
Admin, leader, and team roles — invites and deactivation on every plan.
Room entry policies
Password, allowed email domains, or emailed-code verification on customer rooms — all off by default, on when you need them.
Tenant audit log
Administrative actions in your workspace, recorded — on every plan.
Baseline security on every plan
Signed room cookies, rate limits, strict CSP, revocable expiring links.
Seen, not just listed
The same panels your admins use, from a sample workspace with staged data — what a security review actually looks at.
SSO & SCIM
Your team signs in through your identity provider; seats provision and deprovision from your directory.
Roles, governed
Admin, leader, and team roles — a directory-managed seat can't be hand-edited, and a directory deprovision ends its live session within a minute.
Room entry policies
Password, allowed email domains, or an emailed code before a customer room opens — off by default, per room.
The tenant audit log
Administrative activity on the record — including what your directory did on its own.
Data rights, on every plan
A retention window for raw conversation text with its live count — full export and per-person erasure sit in the same panel.
Links that expire and retire
Every customer link is personal and dies on its own after 14 days; resending retires the earlier one instantly.
Sample workspace · staged data — captured from the running product.
The guarantee about the guarantees.
Enforced, not just promised. Everything above is enforced in our code and checked by automated tests — the same posture as our published trust protocol. We do not yet hold a third-party certification such as SOC 2 — when we do, we'll say so here, and not before.
Enforced in code
Append-only at the database, identity graded on the confirmation itself, exported raw — constraints the system applies, not policies someone remembers.
Checked before every release
Automated tests exercise the real code against each guarantee. A change that breaks one cannot ship.
One posture, two pages
The buyer's side of the same discipline is published as the trust protocol, quoted word for word by our disclosure documents.