Enforced, not promised

The buyer-advocate trust protocol

ValueRoom is built so a buyer can trust the room they're in. This page explains exactly how we handle what you do and say here — enforced in our system and checked by automated tests, not just promised.

Read the full protocol
The buyer's assistant panel in the Northwind sample room: a cited answer from the vendor's published documents, then a judgment question declined and pointed to the account team, above the notice that the buyer's questions are answered here, not stored, and not shared. Staged sample data.
Sample workspace · Northwind · staged data

The protocol at a glance

Thirteen guarantees. Each one is a fact about how the room behaves, and each links to its full wording below.

  1. Your questions to the assistant are privateAnswered in the moment and discarded. Never shown to the vendor's team.
  2. The assistant can't see the seller's internal viewIt has no access to the vendor's scoring, risk reads, or account strategy.
  3. You can connect your own AI, and it stays yoursRead-only, created and withdrawn by you, and it records nothing back.
  4. Room activity is shared — both waysWhat you open and download is visible to both sides, and never feeds a hidden score.
  5. Reactions are explicit, named, and sharedA reaction carries your name and shows identically to both sides. Off means off.
  6. A decision you record is an explicit, named actYour click, your name, shown the same to both sides, changeable any time.
  7. Messages you post are shared, and read by the assistantA recorded, shared channel. Unlike your private questions to the assistant.
  8. Meeting recordings appear only as shared artifactsOne recording and transcript both sides see; recording starts only after your side confirms.
  9. What we record, and what we don'tRoom activity, yes. Your questions to the assistant, no.
  10. Confirmations carry a recorded identity gradeEach confirmation records how you were authenticated; a one-time code is available as a step-up.
  11. AI processingAnswers come from a third-party AI provider (Anthropic). Your question is not stored by ValueRoom.
  12. What happens to data over timeRaw text expires on the vendor's schedule, a person can be erased, a departing organization is exported then deleted.
  13. Published documents are quoted, never improvisedEvery quote is checked word for word against the source, and the source is always shown.
Why you can rely on this page

The guarantee about the guarantees.

Enforced, not just promised. Each guarantee above is enforced in our code and checked by automated tests. We do not yet hold a third-party certification such as SOC 2 — when we do, we'll say so here, and not before.

Enforced in code

Each guarantee above is a rule the system applies itself — a wall, a gate, a firewall — not a policy someone has to remember.

Checked before every release

Automated tests exercise the real code against each guarantee. A change that breaks one cannot ship.

Quoted, never paraphrased

Our disclosure documents quote this page word for word, and a check fails the build if the two ever drift apart.

The full protocol

The exact wording. It is the same text our disclosure documents quote, word for word.

Your questions to the assistant are private

When you ask the in-room AI assistant a free-form question, it's answered in the moment and then discarded — no question text is stored, and your questions are never shown to the vendor's team. The only thing recorded is an anonymous, organization-level tally of AI usage for billing; it can't be tied to you, your room, or what you asked. Alongside that tally, standard short-lived anti-abuse counters exist (rate limits); they contain no question text and no identity, and expire within minutes. Only an outcome you deliberately submit is shared.

The assistant can't see the seller's internal view

The buyer-side assistant is your advocate in the room. It is walled off from the vendor's internal scoring, risk assessments, and account strategy — it cannot reveal them even if you ask, because they are never within its reach. People in the room appear by name and role only, never with a seller's internal label.

You can connect your own AI, and it stays yours

If you'd rather read the record with your own AI assistant than through this room, you can. You create that access yourself and you can withdraw it at any time; the vendor can never create it, see it, or hold it on your behalf. It is read-only by construction — it can never confirm a milestone, withdraw one, leave a note, upload anything, or act in the room as you. It sees exactly what you can see and nothing the vendor keeps to itself. And it records nothing: your assistant's reading produces no notification, no activity entry, and no log of what it looked at.

Room activity is shared — both ways

What happens in the room — which materials you and your colleagues spend time with, download, or share — is visible to both sides, so your account team can help you get what you need. You can open the same activity view they see. None of it feeds a hidden score.

Reactions are explicit, named, and shared

Rooms include the reaction control unless your vendor turns it off. A reaction you tap is recorded with your name and shown identically to both sides in the room's activity view. It is never a hidden rating and never an input to any score. Off means off: no reaction control, nothing of the kind recorded.

A decision you record is an explicit, named act

If your vendor adds a decision to a room, choosing an option is your click — it's recorded with your name and shown identically to both sides, so you both see the same result. You can change or clear your choice any time. It is never a hidden rating and never an input to any score.

Messages you post are shared, and read by the assistant

If your vendor adds a Communications Hub to a room, the messages you and your account team post there are visible to both sides — this is a recorded, shared channel, not a private one. The vendor's AI reads these messages to help them assist your account. It is never a hidden rating and never an input to any score. (This is different from your free-form questions to the in-room assistant, which stay private and are not recorded.)

Meeting recordings appear only as shared artifacts

A meeting recording appears in your room only as a shared artifact: once published, both sides see the same recording and the same transcript — there is no seller-only copy inside the room. The vendor's AI reads the transcript to help them assist your account, and your own AI assistant can read it too. A recording uploaded from another meeting tool was made under that tool's own recording notice. If a meeting is hosted or recorded through ValueRoom, recording starts only after your side confirms — nothing records without the indicator showing, and who allowed it is stamped on the recording. If the vendor captures a live call from their browser, ValueRoom requires them to confirm they have told everyone on the call first — that confirmation is the recording's consent record, stamped on it. A recording's video can be deleted to free storage — the transcript and the record of the meeting remain, visible to both sides.

What we record, and what we don't

So the room works and both sides stay in sync, we do record room activity — when you open the room, time spent on content, files you open or download, how far through videos you watch (quarter milestones only — never second-by-second), the links and buttons you click, and shares — tied to your identity. We also keep an anonymous, organization-level tally of AI usage for billing, and standard short-lived anti-abuse counters (rate limits) — no question text, no identity, expiring within minutes. We do not record your questions to the assistant. “Records nothing” applies to those questions specifically, not to the room as a whole; we'd rather be precise than sweeping.

Confirmations carry a recorded identity grade

When you confirm a milestone or an outcome, the confirmation records how it was authenticated. Your team can also require a one-time code emailed to your address before a confirmation counts — an available step-up, off by default.

AI processing

The assistant's answers are generated by a third-party AI provider (Anthropic). Your question is sent to produce the answer and is not stored by ValueRoom.

What happens to data over time

The vendor controls how long raw conversation text pulled from their connected tools is kept — once a retention window is set, older raw text is permanently removed on a nightly schedule (confirmed milestones and extracted signals stay). A person can be erased on request through the vendor's team: their name, email, and profile are permanently scrubbed, while anything they co-signed stays on record attributed to an erased person — so the shared history can't be quietly rewritten. And when an organization leaves ValueRoom, its data doesn't linger: a machine-readable export is offered, and after a grace period (30 days by default) everything is permanently deleted — all that survives is a minimal record that the deletion happened.

Published documents are quoted, never improvised

A vendor can publish reference documents for you — a security overview, data-processing agreement, product FAQ. When the assistant answers from them, every quote is checked word-for-word against the published document before you see it, and the source is always shown. If the documents don't answer your question — or it's a judgment call — the assistant says so and points you to your account team instead of guessing. Your questions about these documents are private, like all your questions here.