Controls
Five controls hold the case sealed — from intake to conclusion.
Each control below is enforced in the case file, not in the marketing surface. What you read here describes the platform’s behavior on a real case, not a hypothetical one; the case folder remains the source of truth.
Sealed-bid masking, per case
Sealed compartments are scoped to a single case file. No plaintext offer is rendered to any party — bidder, coordinator, counsel, or counterparty — until the configured reveal window opens. The reveal window itself is recorded in the case policy, not improvised at show time. Unmasking appends to the audit log; nothing in the seal is overwritten on reveal.
- Scope is the case file, not the platform
- Reveal is a per-case policy event, not a UI affordance
- Unmasking appends to the audit log, never overwrites it
- Counter-offers inherit the same seal as the opening bid
Role-aware dashboard access
Dashboard visibility is bound to the party's role on the case: bidder, coordinator, counsel, or observer. Each role sees the rows its role entitles it to and no others; cross-role queries are not exposed through the UI or the public surface. Role assignments are recorded at intake and appended on amendment; a role change never silently rewrites who saw what.
- Role set is recorded at intake and appended on amendment
- Bidder — own offers and matched comparables surface only
- Coordinator — all offers and audit events for the case
- Counsel — all offers, written rationale, and export surface
Single-use invite tokens
Bidder and counsel access is gated by single-use invite tokens issued at intake. A token is consumed on first use; subsequent attempts with the same token are rejected, and the rejection is appended to the audit log. Revocation is recorded with a documented reason, and any reissue requires a coordinator-role action appended to the file. Link sharing cannot escalate privilege beyond the role the token was issued for.
- Token is one-shot, not session-long
- Revocation is recorded with a documented reason
- Reissue requires a coordinator-role action appended to the file
- Link sharing cannot escalate privilege
No public case disclosure
No case file is indexed publicly. The platform does not publish case lists, bidder rosters, or result summaries outside the authenticated dashboard. Public pages (this page, /how-it-works, /pricing, the demo room) are demo-only and carry no live case data; search engines receive noindex instructions for case surfaces. Press and reference requests route to a coordinator-role action, not to an open form.
- Case lists are gated behind authentication
- Search engines receive noindex instructions for case surfaces
- Demo data is synthetic — no real comparables or real bid values
- Press and reference requests route to a coordinator-role action
Audit trail behind authentication
The audit log — every offer, counter, rewrite, reveal, role change, invite, and disclosure event — stays behind authentication. The log is append-only; amendments append rather than replace. Counsel reads the log in the case file, not via a public feed, and the export surface (PDF) is the canonical read path for any party who needs to defend the record outside the platform. Public surfaces carry no audit data.
- Append-only — no deletion, no edit, no redact
- Readable only by authenticated parties on the case
- Export surface (PDF) is the canonical read path for counsel
- Public surfaces carry no audit data
Controls are the legal-financial register: declarative, documented, and reconstructible. Adapted per case file, with amendments appending rather than replacing the record.