Your deal data stays your deal data

Due diligence material is some of the most sensitive information a fund handles. We built Lab08 on the assumption that it never leaves your control: European infrastructure, private instances, our own models, and nothing fed back into training.

ISO 27001 certified Information security management

Hosted in Europe. Isolated per client. Never used to train anything. Deleted when you say so.

Four commitments, no asterisks

These are architectural choices, not policy promises - the platform could not behave otherwise.

  • European infrastructure

    Hosted on AWS in European regions. Your material is processed and stored inside the EU, under EU law.

  • Private instances

    Each client runs in their own isolated instance. No shared indexes, no cross-client retrieval, no accidental bleed between funds.

  • Our own models

    Lab08 runs on proprietary models and agent pipelines built around our diligence method - not a generic assistant wired to a prompt.

  • Never trained on your data

    Nothing you upload or screen is used to train or fine-tune our models, and nothing is passed to third parties for that purpose.

Proprietary models, run on our terms

Lab08 runs on our own proprietary models and agent pipelines, built around our diligence method. That means the reasoning behind a screening is ours - not a generic assistant's - and it means we decide where your data is processed and what happens to it afterwards.

Your material is never used to train our models. Not yours, not anyone else's.

  • Built for diligence, not chat

    Our agents are constrained by the Lab08 framework: fixed question sets, graded evidence and declared gaps.

  • Controlled processing path

    We decide where inference runs. No routing of your material through consumer AI products.

  • Traceable output

    Every conclusion carries its source and date, so you can audit what the model actually relied on.

  • No training feedback loop

    Your documents and findings stay in your instance. They never become training data - for us or anyone else.

European by default, isolated by design

Built on AWS in European regions, with each client running in their own instance rather than a shared pool.

  • AWS, European regions

    Managed, hardened cloud infrastructure with encryption in transit and at rest.

  • Access on least privilege

    Role-based access inside your instance, and a small named team on our side with logged, time-bound access.

  • Encrypted end to end

    TLS in transit, encryption at rest, and secrets managed outside the application layer.

  • Audit trail

    Who saw what, and when. The same evidence trail that backs findings also records access.

  • Deletion on request

    Say the word and your instance data is removed, including derived artefacts and cached sources.

  • Sub-processors on record

    We keep a current list of the services in the processing path, available on request with our DPA.

What you can decide, and undo

A screening needs no company access at all - public signals only. Everything beyond that is something you grant, and can withdraw.

  1. Start with no access at all

    An agentic screening uses only public signals. You get a full read without the target ever being contacted, and without uploading anything.

    Access None

  2. Grant access per engagement

    Documents, systems and data-room material are scoped to one engagement - not to your account forever.

    Access Scoped

  3. Bring your own boundaries

    If your fund has requirements on residency, retention or named personnel, we set the instance up to match before we start.

    Access Your rules

  4. Take it back

    Withdraw access or request deletion at any point. We confirm in writing what was removed.

    Access Revoked

Questions from your IT
or compliance team?

We are happy to walk through the architecture, the data flows and our processing terms in detail - before you put a single document anywhere near the platform.

Talk to us