Your Deal Model Is the Most Sensitive File You Own. CREDevSim Never Sees It.
A development model is not a neutral document. It holds your purchase price, your debt terms, your LP economics, the promote you negotiated, the earnest money and contract timelines you're working against, and, often most sensitive of all, unannounced off-market site control before a contract is even signed. In the wrong inbox that file can move a price, tip a competitor onto an assemblage, or front-run your land. Everyone who works on a deal knows this, which is why the file gets guarded, emailed carefully, kept off the shared drive.
So it is strange how rarely anyone asks where that file goes the moment they type it into a modeling tool.
The question nobody asks the software
Most modern software is a cloud service. You enter your numbers into a browser, and those numbers travel to a server you do not own, land in a multi-tenant database you cannot see, and are handled by systems, and the staff who administer them, under governance controls you never reviewed and cannot verify. The vendor will have a privacy policy full of words like "encrypted" and "secure." But encrypted-in-transit does not mean invisible-to-them. It means invisible to everyone except the company running the service. Your deal now lives on their infrastructure, subject to their access controls, their subpoenas, their breaches, and their retention policy.
For most software, that is a fair trade. For a confidential underwriting file, it is the exact exposure you spend the rest of your process trying to prevent.
It has gotten sharper with AI
Many web-based platforms now include data-use clauses in their terms of service that permit user inputs to inform downstream model training or product improvement. Read that against an underwriting file. When the input is your proprietary cap-rate assumptions, your rent-growth projections, and your return math, you have handed a third party contractual latitude over your confidential deal terms. That is a risk most deal teams never budgeted for when they clicked "I agree."
This is not about one dramatic breach. It is the quieter, structural exposure of confidential inputs living on shared infrastructure, under terms you did not write.
CREDevSim is built the opposite way: architecture, not a promise
CREDevSim uses a zero-cloud, local-first architecture. It is a native desktop application that runs on your own computer. Your inputs, your saved deal files, every output and PDF stay on your local hard drive. They are never uploaded, never synced, never transmitted.
The only time CREDevSim touches the network is for an initial sign-in and, after that, a weekly check-in with a license server to confirm your account is active. That check is the only thing that ever leaves the app, and it carries none of your deal data: no numbers, no files, nothing you typed. In between, the app runs fully offline for up to seven days, so you can model a deal on a plane and your work never waits on a connection. There is no server receiving your numbers and no database holding your deal flow. Because that data never leaves your machine, there is nothing on my end to leak, breach, or hand over.
Even I cannot see it
People ask whether I can see their inputs. I cannot. Not "I promise not to look." I have no technical path to them.
As a former Big 4 auditor, I know exactly what a real system audit trail looks like, because reconstructing one was my job. So I built the opposite on purpose: there is no telemetry on your underwriting cells, no event log of your assumptions, no server-side copy to reconstruct. There is no server in that loop at all. That is not a matter of trusting me. The plumbing does not exist.
I should be clear about one thing, since I also advise on deals directly. If you ever decide to send me a file, say for a tax review, that is your choice, and I handle it the way I have always handled confidential financials, under professional privilege. That is a world apart from a tool that quietly takes a license to your inputs the moment you type them. What I am claiming on this page is narrower, and only about the software itself: the app has no way to reach me.
Nothing to vet, and no calendar to lose
There is a quieter benefit for anyone raising institutional money, and it is measured in weeks. Institutional LPs love SOC 2 compliance, right up until their internal IT security team sits on your vendor questionnaire for three weeks while your capital raise waits. When your data never leaves your machine, there is no vendor to onboard, no SOC 2 report to hand your LP's counsel, no data-processing agreement to negotiate, no sub-processor questionnaire to answer. A third party never touches the data, so there is no third party to vet. An LP protective of proprietary deal flow has nothing to object to, and nothing sits between your model and your investment committee.
The honest boundary
I will be precise, because overselling security is its own red flag. What CREDevSim controls is the application layer: the software gives your deal data no way out. It cannot send what it was never built to send. What it does not control is your endpoint, the machine itself. That is the same responsibility you already carry for every Excel file on your drive, and it is handled the same way: standard full-disk encryption (BitLocker on Windows, FileVault on Mac) protects the device, and because the deal files are ordinary local files, they work with your normal backup routine (OneDrive, Time Machine, or your firm's managed backup), so local-first never means you are one dead laptop away from losing a deal.
The distinction matters: I am not claiming to secure your hardware. I am guaranteeing something narrower and, I think, more valuable: that the tool itself never becomes the leak.
I spent years being handed other people's most sensitive financials and trusted to handle them carefully. When I built CREDevSim, the version of "careful" I wanted was not a longer privacy policy. It was a design that does not require trust, because the data never leaves your hands in the first place.
CREDevSim is free and runs entirely on your machine. If your deal data is the kind of thing you would never email without thinking twice, that is exactly who it is built for. Download and run your next deal locally →