Six answers, in order of how often we hear them

You do. Every target list, every written summary, and every input you provide through the criteria intake is owned by your fund end to end. DealForge holds a non-exclusive license to process inputs solely to deliver the contracted service. On contract termination we return or delete every artifact at your direction, and we make the relevant deletion logs available on request.
Only employees on a strict need-to-know basis — the analyst assigned to your account and the small delivery-ops team that runs quality checks. Nothing from your flow is ever shared with another client, used to train models we will monetize, or surfaced to peers. We sign a mutual NDA before any data exchange, and we will countersign yours.
Every delivery exports to JSON and CSV so you can pull targets into Affinity, Attio, Salesforce, HubSpot, SourceScrub, or a custom Postgres pipeline without engineering work. CSV uploads back to your CRM are supported on every plan; webhook delivery into your pipeline on a new target landing is built into Growth and Enterprise. We will write a one-time connector for any CRM you use for an Enterprise onboarding fee.
In the 30-minute call we run DealForge live against your stated thesis — your sectors, revenue band, geography — and send you the actual targets we surface, plus a written "what we saw" summary of fit, ownership signals, and outreach angles. You walk away with real signal and zero obligation to subscribe.
Yes — DealForge is currently a paid early-access cohort of roughly 20 funds, capped plan tiers while the cohort is open. Members of the cohort lock in their current pricing for the lifetime of their subscription and get a direct line to the product team during weekly cohort office hours. When we move to GA, those tiers are grandfathered; new funds after that point will pay the GA rate.
Our data sources are read-only public and licensed feeds — we never scrape an authenticated target's site, and nothing requires logging into a third-party portal under your credentials. Stored data is encrypted at rest with AES-256 and in transit with TLS; each client is isolated by a single-tenant client_id, so two different funds literally cannot see each other's flow even at the database level. We will sign your firm's DPA, and on request we will hard-delete every piece of data tied to your account within 30 days.