DealFile

Data Handling & Security

For the IT and security teams of firms whose brokers use DealFile. Last updated August 2026.

What DealFile is

DealFile is a filing tool for commercial real-estate brokers. A broker forwards deal email — manually, or via an inbox-forwarding rule — to a private DealFile address. DealFile reads each message, matches it to the right deal, and files it and its attachments into per-deal folders, so the broker's deal records assemble themselves. It is operated by ZoeIsabelOlivia LLC.

What data DealFile receives

Only email a broker forwards to their DealFile address, and the files attached to it. When a broker sets up inbox forwarding, that can include mail that isn't a deal. DealFile reads what it receives to classify it, but — see retention below — it does not keep what isn't a deal.

Today, DealFile receives only the email forwarded to its address — it has no standing connection to a broker's mailbox — and it never sends email as the broker.

Who processes it (subprocessors)

DealFile runs on established infrastructure providers, each under its own security and privacy commitments. Data is processed in the United States.

ProviderRole
PostmarkReceives forwarded email
Supabase (on AWS)Database, file storage, authentication
Anthropic (Claude)Reads email/document text to classify and file it
Render, RailwayRun the application and the filing worker
CloudflareDomain and network routing

Content submitted to Anthropic's business API is, per Anthropic's terms, not used to train its models. DealFile does not sell data or use it to train models of its own; it is used only to provide the filing service.

Where it's stored, and for how long

Deal email and documents are stored in DealFile's database and file storage (Supabase, on AWS, US region) for as long as the broker's account is active, so the filing stays useful.

DealFile keeps deals, not mailboxes. Mail that DealFile determines is not a deal is held for up to 90 days — long enough for the broker to recover anything misjudged — and then its content (message body, attachments, stored formatting) is automatically deleted; only a minimal record that a message was received and set aside is retained. A broker can request deletion of their account at any time. Once actioned — within 5 business days — everything is permanently erased: every email, attachment, and stored file, plus the account itself, with nothing retained and no recovery.

Security

  • Traffic is encrypted in transit (HTTPS/TLS).
  • Each broker's data is isolated at the database level (Postgres row-level security), not only in application code — one broker's deals are not reachable from another account.
  • Production access is limited to DealFile's operator.

Certifications, stated plainly: DealFile does not currently hold a SOC 2 or ISO 27001 certification. A SOC 2 program is planned but not yet in place. We'd rather tell you that directly than imply otherwise.

Terms, privacy, and questions

DealFile's Terms of Service and Privacy Policy are available on request, and a data-processing agreement can be discussed for firm-wide use. For any question — a security review, a specific data-handling concern, a deletion request — contact glenn@dealfile.io.