Data flow
Manual underwriting stays in your browser: inputs, the engine, results, exports. Your deal leaves it on four occasions, each started by you: the three AI actions, and a URL that carries the deal. That covers a share link you send and the IC memo button on the desk, because the memo is a page and opening it is a request with the whole deal in the request line. Market data flows the other way and never carries deal data out.
- Your browser
inputs, deterministic engine, results, TRACE, xlsx, print
- Your browser
document staged; workbooks reduced to bounded cell text locally
- Underwrite server
size and reference checks, rate limit; staged PDFs read back from private storage and deleted when the parse settles
- Anthropic APIExternal AI
reads the document, returns structured values and the sentences it quotes for them
- Your browser
current inputs and computed results, serialized
- Underwrite server
validation and rate limit; keeps no copy
- Anthropic APIExternal AI
returns prose for review; cannot change a number
- FREDExternal provider
Treasury curve, SOFR, CPI, inflation expectations
- Underwrite server
holds the provider key; stamps observation date, cadence, freshness
- Your browser
renders the series with their own as-of dates
- Your browser
the whole deal, encoded into the URL itself; nothing is uploaded to make the link and there is no link database. The desk's own IC memo button builds one of these URLs
- Wherever you send itOut of Underwrite's hands
the link is the deal; anyone holding it can open it
- Underwrite server
opening the link sends the whole URL, deal included, to the server in the request line; the server reads the deal name for the page title and the preview card, serves the page, and keeps no copy. The request line exists in the hosting platform's access log, which this product does not control and therefore does not promise to delete
- Your browser
an event name, a random id this browser made for itself, and coarse facts: which assumption field was edited, which limitation appeared, which export ran. Never a value, a quote, a name, an address or a file
- Underwrite server
an allowlist of event names and properties; unknown events and free text are refused; no IP address or user agent is kept
- Private store
read only by the founder's own report; deleted by a retention pass he runs, window 90 days, which leaves a receipt; no third-party analytics, no session replay, no keystrokes
- StripeExternal provider
the card is entered on Stripe's hosted page; card numbers never touch Underwrite
- Underwrite server
a signed webhook records customer id, email, plan and status in a private ledger; the signature is verified before anything is read
- Form serviceExternal provider
your email and what you typed go to a form service and land in the founder's inbox; type nothing there you would not email
The diagram also shows three paths that carry no deal data: usage events, off in Confidential Mode and deleted by a retention pass the founder runs (window 90 days, not a timer); a subscription, where the card is entered on Stripe's page and Underwrite keeps a customer id, email, plan and status; and the two forms, which reach the founder through a form service. There are no accounts, no server-side deal database, and nothing that reads deal contents.
The AI boundary
Three features send data to Anthropic's API, each only when you click it, each through Underwrite's server, and each returns material a human reviews. Two of them change no number: the deal review and the memo's executive summary are written about figures the engine has already produced, and what they return is prose, checked against the engine before it is shown and refused if it disagrees.
The parser is different. It returns field values, those values are written into the inputs panel, and the engine recomputes from them: exactly what happens when you type a value yourself. What it cannot do is produce a result. It fills inputs; it never returns an IRR, a multiple, a verdict or a grade, and no figure it returns is used as an output. On a hotel deal it is also asked to turn a stated ADR and occupancy, or a stated RevPAR, into a monthly revenue per key. That is the one arithmetic step anywhere in the extraction, it lands in an input you can see and change, and /methodology/hotel states the conversion.
| Feature | Sends, on click | Returns | What it can never do |
|---|---|---|---|
| AI parser | The document or pasted text you hand it | Structured field values, each with a verbatim source quote or a hand-verify flag | Produce a result: extracted values enter the inputs panel for your review, exactly like typed ones, and no figure it returns is used as an output |
| AI deal review | Current inputs and the engine's computed results | Qualitative flags, diligence questions, one-line read | Change any output, verdict, grade, or exported number |
| Executive summary | Current inputs and the engine's computed results | Two to four sentences of prose restating the engine's own figures | Recompute anything; it restates, and you review before it is kept |
The calls run under Anthropic's commercial API terms, which do not use the input for training. Underwrite trains nothing.
On the desk, provenance is labeled in the engine's own vocabulary: extracted values read Extracted from source with the sentence that attested them where there is one, deterministic outputs read Calculated by model, and anything you override reads User assumption. Judgment calls the engine cannot make are routed to analyst review and say so.
The engine, and what is advisory
Every financial figure is computed by deterministic TypeScript: same inputs, same outputs, no prompt, no sampling. The verdict is the conjunction of two published rules, computed once in lib/engine/decision.ts and consumed by every surface that shows it: project IRR at or above 15.00% and minimum DSCR at or above 1.00x (all-equity deals skip the coverage test because no debt service exists).
Everything else that sounds like advice is labeled advisory and never gates: lender-standard tests shape the grade, solvers propose values you apply yourself, calibration suggestions compare your inputs against market context, and AI review is qualitative prose that cannot alter an output. The six files the decision depends on, the verdict rule included, are rendered from the live source at /methodology/engine; the full method is at /methodology.
Document handling
The figures below are the capability report of the deployment serving this page, the same report the upload panel reads.
- PDF size ceiling
- asking the deployment...
- PDF page ceiling
- asking the deployment...
- the parser service's own limit; the product tells you before you hit it
- Excel workbook ceiling
- asking the deployment...
- workbooks are opened in your browser; only bounded cell text is sent
- Parse rate limit
- asking the deployment...
- enforced server-side; the limiter and this number share one constant
The mechanics behind those numbers: a PDF at or under the direct ceiling travels inside your parse request. A larger PDF is staged, from your browser, into private blob storage under a server-issued token scoped to PDFs, to one folder, to the size ceiling, and to a few minutes. The store is private: the document never sits at a public address, the parser service cannot fetch it by URL, and only Underwrite's server token can read it back. The server verifies the staged reference is its own, refuses foreign hosts and malformed paths, and deletes the blob the moment the parse settles, on success and on every failure path. Excel workbooks never travel as binary: they are opened in your browser and only their cell text, normalized and capped in size, is sent, with formulas and macros never executed.
Underwrite's operator log records sizes and timings, never content. Rate limiting is per IP and applied on the server, with the ceiling above read from the limiter's own constant. The count is held in memory per server instance, so it is a service protection, not a hard guarantee: several instances, or a restart, can let more through.
Confidential Mode
Confidential Mode is one switch on the desk. With it on, these are off:
- AI parsing is disabled: text, PDFs, and workbooks cannot be sent from the parser panel.
- AI deal review is disabled, and the Review tab steps aside so you are never parked on a dead panel.
- The memo's AI executive summary is disabled on the memo page, and the request is refused at the call as well as at the button.
- Share links are disabled, because they encode the deal in the URL.
- The memo link is disabled for the same reason; the printable memo remains available from the desk itself.
- Usage events stop: with Confidential Mode on, no page sends a beacon at all, not even the fact of an edit.
- The one feedback question that follows an export is not offered, because what you type into it goes to a form service.
What keeps working: manual inputs, the full deterministic engine, scenarios and sensitivities, print, xlsx export, and the local deal library. Two limits: Confidential Mode is a setting kept in this browser's storage, not an account setting. It stays on across reloads and across the desk and the memo page in this browser until you turn it off or clear the site's data, and it does not follow you to another browser or device. In a browser that blocks site storage it holds only until the page reloads. And the page itself still fetches market rates from Underwrite's server; those requests carry no deal data in either direction. Your organization's document-handling policy still governs what you are authorized to paste anywhere, including here.
Source provenance and your changes
An AI-extracted value arrives either with a source sentence or with a flag saying it has none, and the flag says which of three reasons applies. For pasted text and workbooks the server holds your source, so it asks two questions of every quote the model returns: is this sentence literally in the source, and does it state the value being claimed. A quote that fails either is not provenance. It is still shown, beside the hand-verify flag, and labeled as reported rather than attested. The server passes a PDF to the model without reading its text, so neither question can be asked of a PDF quote: every row from a PDF parse carries the hand-verify flag, and the sentence it reports is the model's account of the document rather than a verified quotation from it. Tenant rows extracted from a rent roll carry no quote at all: they arrive as an audit row with the term the document stated, and the per-tenant sentence is not tracked yet.
The desk states each input's standing in two places. In the parser's list of what it extracted, a value shows its quote, or an amber flag to verify it by hand when no quote survived; every tenant row from a rent roll is in that list with the amber flag. In the inputs panel, each parsed field carries a gold dot whose tip shows the quote or says no verbatim quote survived. Tenant cards carry no dot, so a tenant row's standing is shown only in the parser's list, and hand-entered fields claim no source at all. The moment you edit an extracted field, the dot gives way to a User assumption ring: the quote attests what the source said, not what you chose, so a value that departs from its evidence is visibly yours.
Source quotes are state in the tab that parsed the document. They are not written into a saved deal, they are not encoded into a share link or a memo link, and loading a deal from the library clears them. A colleague who opens your link gets the deal's values and no evidence behind them, and so do you when you reopen your own saved deal: the desk shows those fields with no provenance rather than with provenance it cannot stand behind. The workbook and the printed memo do not carry the quotes either. Nothing Underwrite produces is a substitute for keeping the source document beside the deal.
The change record works the same way: the desk keeps the deal as it arrived (from a parse, a link, the library, or the defaults) and diffs the live model against it, so every edited assumption is listed with its loaded value, its current value, and the measured impact of that one edit, with one-click restore. This record is derived from the live session, not stored: Underwrite keeps no server-side history of your edits, and a saved deal is a snapshot, not a log. There is no edit history across sessions, because your deal does not live on Underwrite's servers.
Model limitations
One register in the engine source owns every limitation's wording, and the desk, the memo and this page render the same entries. A limitation carries no invented impact number: a line the engine does not model has no engine impact to measure. Where a deal gives a limitation measurable scope, the desk and memo state the share of gross potential revenue it sits behind.
Operating expenses are carried gross. CAM, tax and insurance reimbursements from commercial tenants are not credited back to EGI, so NOI is conservative by the amount of any recovery this asset actually collects.
Applies: Any deal with commercial space, including net-leased assets. Workaround: None inside the cash flow. The memo's recovery screens read reimbursement structure as diligence risk; they never credit a dollar back to EGI.
Commercial space on an aggregate rent assumption carries no rent roll, so tenant improvements, leasing commissions, rollover downtime and free rent sit outside the cash flow.
Applies: Commercial space entered as aggregate SF and rent, with no tenant rent roll. Workaround: Add a tenant rent roll: tenant improvements, leasing commissions, rollover downtime and free rent are modeled per tenant, and expired leases re-lease at market.
Anchor-loss rent reductions and termination rights on inline tenants are not read from leases and never enter the cash flow, with or without a rent roll.
Applies: Multi-tenant retail and office. No workaround inside the model.
Taxes, depreciation and partner-level management fees are not modeled. Every IRR and multiple on this desk is a pre-tax, pre-fee project-level figure.
Applies: Whenever the after-tax overlay is off, which is the default. Workaround: Enable the after-tax overlay: straight-line depreciation, optional cost segregation with bonus depreciation, optional NOL carry-forward, and optional flat state rates are modeled.
A pass-through entity is assumed. State rates are added flat to federal; SALT-cap and deductibility interactions, Section 1031 exchanges, and entity-versus-partner distinctions are not modeled.
Applies: When the after-tax overlay is on. No workaround inside the model.
The balloon is assumed paid off at sale with no exit-debt cost. Interest-only periods and floating rates are also not modeled.
Applies: Every levered deal. No workaround inside the model.
Tier amounts are computed against the LP's compounded hurdle over the full hold. Annual interim distributions feed the IRR cash flows but do not step LPs through hurdles year by year.
Applies: Every deal with a waterfall. No workaround inside the model.
The wider institutional gap map, including what stays with counsel, appraisers, and lease abstracts, is at /methodology/beyond-phase-1.
Live data
Macro series (Treasury curve, SOFR, CPI, inflation expectations) come from FRED, fetched by Underwrite's server; provider keys never reach your browser, and the requests carry no deal data. Every figure keeps three facts separate: the observation date it describes, the cadence it can possibly move at, and the moment Underwrite last called the provider. A monthly CPI print is labeled as the month it describes and never dressed up as an intraday read. When the provider is unreachable or unconfigured, the product serves deterministic seeded values that are labeled as fallback and never impersonate a market observation.
Reading the feed...
Beyond the FRED series, many Phase 3 market overlays run on seeded calibrations until direct data licenses exist; each is tagged live, hybrid, seeded, or derived in the module inventory, and the memo's module notes say which is which.
Exports and sharing
The Excel workbook is written in your browser by the export code, from the live model; it does not round-trip a server. Print produces the IC memo from the same state. Share links and memo links encode the deal's inputs into the URL itself: nothing is uploaded to create one, there is no link database, and the link is the deal. Opening one is a request to Underwrite's server with the whole deal in the URL: the server reads the deal name for the page title and the preview card, serves the page, and keeps no copy, and the request line exists in the hosting platform's access log, which this product does not control and therefore does not promise to delete. The URL does not carry the parse: source quotes stay in the session that made them. Treat a share link like the document it carries, because anyone holding it can open that deal; that is why Confidential Mode disables both link flows.
Deletion and access
Saved deals exist in your browser's local storage, on your machine, and nowhere else. Delete any deal from the library, or clear the site's browser data to remove everything at once. Underwrite operates no server-side deal store, so there is no copy to request, and no one at Underwrite can pull up a deal from a database, because there is none. Access is whoever can use your browser profile, plus anyone you hand a share link, plus whatever the hosting platform's access log retains of the request lines of the memo and share links that were opened. Those request lines carry the encoded deal, the founder can read that log, and this product neither controls its retention nor promises to delete it. Confidential Mode turns both link flows off, which is the way to keep a deal out of it.
The transient exceptions are the AI requests themselves: for the seconds a parse, review, or summary is in flight, the material you sent exists in the request path (and for a staged PDF, in private blob storage that is deleted when the parse settles). Those requests are handled by Anthropic under its commercial API terms, which do not use the input for training.
Two records that are not deal data do persist. Usage events carry an event name and three random ids this browser made for itself: one for the browser, one for the tab's session, and one for the deal being worked on, which a share link also carries so a forwarded copy is not counted as somebody else's second deal. None of the three is derived from your property, your document, your numbers, or a hash of any of them. Clearing site data severs them from anything recorded before.
Deleting those events is a pass the founder runs, not a background timer. The window is 90 days: a day older than that is deleted when the pass runs, and each pass writes a receipt saying what it deleted and when. Until a pass has run, the events are still there. If the store is unavailable the event is not recorded at all, and the diagnostic line left behind names the event and nothing else: no ids, in a platform log this product does not control and does not promise to delete.
A subscription record (customer id, email, plan, status) is a business record, kept for as long as the business needs it and deliberately not covered by the usage-event window above: email ali@getunderwrite.com to have it removed.
Security status
What exists and is checked by automated gates against the shipped product:
- Provider API keys are server-side only; a gate scans the built client bundle for key material and provider endpoints on every run.
- Staged documents go to private storage, single-use, deleted when the parse settles; a gate regression-tests the refusal of foreign hosts, wrong folders, path traversal, and lookalike references.
- Upload tokens are scoped to PDFs, one folder, the size ceiling, and minutes of validity.
- AI endpoints are rate limited per IP, with the enforced number published by the capability endpoint.
- Usage events are allowlisted by name and by property: the schema has no free-text field, so a document, a value or a quote cannot be recorded even by mistake. An unexpected field is refused outright rather than quietly dropped, and a gate proves both on every run.
- Payments would run on Stripe's hosted checkout, and live checkout stays closed while any commercial fact is pending; the webhook that records a subscription verifies Stripe's signature before it reads a byte, and the ledger holds no deal data.
- There are no accounts, so there is no password database, no session store, and no credential surface to breach.
What Underwrite does not have:
- No SOC 2 or ISO 27001 certification, and no third-party penetration test report.
- No signed data processing agreements. An institution that requires one should run sensitive deals in Confidential Mode or manually until that paperwork exists.
- No SSO, no team permissioning, no field-level audit log: single-analyst workflow today.
- No encryption-at-rest story to tell about deal data on Underwrite servers, because no deal data rests on Underwrite servers.
The ceilings, the rate limit, the feed rows and the limitations above are read from the running system. A trust gate refuses a build whose prose and running system disagree. It is run by hand against a candidate before a release, not by the continuous integration that runs on a push: that job checks types and lint, then asserts the canonical figures against production after the deploy.