Security

Each case is sealed. Each record is reconstructible.

The Velmark confidentiality model in five controls — written for counsel, beneficiaries, and trustees who need to read how a case is held private end to end. No offer is rendered in plaintext, no disclosure escapes authentication, and no event in the audit trail is overwritten once written.

Controls

Five controls hold the case sealed — from intake to conclusion.

Each control below is enforced in the case file, not in the marketing surface. What you read here describes the platform’s behavior on a real case, not a hypothetical one; the case folder remains the source of truth.

01

Control 01

Sealed-bid masking, per case

Sealed compartments are scoped to a single case file. No plaintext offer is rendered to any party — bidder, coordinator, counsel, or counterparty — until the configured reveal window opens. The reveal window itself is recorded in the case policy, not improvised at show time. Unmasking appends to the audit log; nothing in the seal is overwritten on reveal.

  • Scope is the case file, not the platform
  • Reveal is a per-case policy event, not a UI affordance
  • Unmasking appends to the audit log, never overwrites it
  • Counter-offers inherit the same seal as the opening bid
02

Control 02

Role-aware dashboard access

Dashboard visibility is bound to the party's role on the case: bidder, coordinator, counsel, or observer. Each role sees the rows its role entitles it to and no others; cross-role queries are not exposed through the UI or the public surface. Role assignments are recorded at intake and appended on amendment; a role change never silently rewrites who saw what.

  • Role set is recorded at intake and appended on amendment
  • Bidder — own offers and matched comparables surface only
  • Coordinator — all offers and audit events for the case
  • Counsel — all offers, written rationale, and export surface
03

Control 03

Single-use invite tokens

Bidder and counsel access is gated by single-use invite tokens issued at intake. A token is consumed on first use; subsequent attempts with the same token are rejected, and the rejection is appended to the audit log. Revocation is recorded with a documented reason, and any reissue requires a coordinator-role action appended to the file. Link sharing cannot escalate privilege beyond the role the token was issued for.

  • Token is one-shot, not session-long
  • Revocation is recorded with a documented reason
  • Reissue requires a coordinator-role action appended to the file
  • Link sharing cannot escalate privilege
04

Control 04

No public case disclosure

No case file is indexed publicly. The platform does not publish case lists, bidder rosters, or result summaries outside the authenticated dashboard. Public pages (this page, /how-it-works, /pricing, the demo room) are demo-only and carry no live case data; search engines receive noindex instructions for case surfaces. Press and reference requests route to a coordinator-role action, not to an open form.

  • Case lists are gated behind authentication
  • Search engines receive noindex instructions for case surfaces
  • Demo data is synthetic — no real comparables or real bid values
  • Press and reference requests route to a coordinator-role action
05

Control 05

Audit trail behind authentication

The audit log — every offer, counter, rewrite, reveal, role change, invite, and disclosure event — stays behind authentication. The log is append-only; amendments append rather than replace. Counsel reads the log in the case file, not via a public feed, and the export surface (PDF) is the canonical read path for any party who needs to defend the record outside the platform. Public surfaces carry no audit data.

  • Append-only — no deletion, no edit, no redact
  • Readable only by authenticated parties on the case
  • Export surface (PDF) is the canonical read path for counsel
  • Public surfaces carry no audit data

Controls are the legal-financial register: declarative, documented, and reconstructible. Adapted per case file, with amendments appending rather than replacing the record.

Velmark · Case access

Public surfaces carry no live case data — request the file.

The case file, the audit trail, and the export surface are accessible only on an authenticated case file. Request access through a coordinator to read the full record on a real matter.

Request access through a coordinator