EARLY ACCESSPartnering with a small group of CRE firms ahead of general availability.Request access →

Security and trust

We tell you exactly what our governance enforces, and what it does not.

CRE Skills Pro runs as a local Claude Code plugin. By default no deal data leaves your machine. Here is the enforcement boundary, stated plainly so your security team can review it.

SOC 2 in progressDPA availableNo training on your dataManaged-settings deployment7-year audit retention

Enforcement model

Guarded (self-install, default)Enforced (managed, Enterprise)
The PreToolUse hook blocks the write. The audit log records every action. Self-approval is rejected at the hook. A user with shell access can edit or remove a hook. Strong process enforcement and a tamper-evident audit. Not an IT security control.Managed settings override the user. The server issues attested approval tokens. Four-eyes cannot be self-satisfied. An external WORM store holds the audit, uneditable locally. An operator-proof control plane.

Data handling

Local-first. Deal state is gitignored on your machine. The most sensitive class of data (SSN, EIN, wire details, API keys) is never auto-saved. The shared file stores aggregates and hashes, never raw payloads.

Audit and managed settings

The audit log is append-only JSONL with an artifact hash chain, and a file-change monitor flags any external mutation. Enterprise admins pin a fleet with strictKnownMarketplaces and disableBypassPermissionsMode.

The IP boundary, stated plainly

Plugin skills are plaintext Markdown in Claude Code’s local cache. There is no client-side DRM. License enforcement is a soft entitlement check plus your firm’s terms of use. Where IP protection is paramount, the value is in the governed workflow, not in making files unreadable.

Download the security package