The Blog
Notes · 12 Aug 2026 · 7 min read

Is Valuation Data Stored Securely in AI Review?

Is valuation data stored securely when an AI reviews your report? Know what to ask about encryption, retention, access and model training before upload.

A valuation report is not just a document. It may contain borrower details, tenant information, lease terms, comparable evidence, lender instructions and commercially sensitive conclusions. So, is valuation data stored securely when it is submitted to an AI review tool? The answer should be clear before a single draft report is uploaded.

For a registered valuer, this is not a technicality to leave for later. A review tool may read the whole report to identify a capital value that differs between the executive summary and conclusion, a floor area that does not reconcile with the comparable schedule, or a missing EWS1 disclosure. That means it is handling the substance of the instruction, not merely checking spelling.

The right question is not simply whether a provider says it is "secure". It is what happens to the report at each stage: during transfer, while it is being processed, after the review is complete, and if the provider develops or improves its systems.

Is valuation data stored securely during review?

Security starts with how the report travels from your browser to the review platform. The connection should be encrypted in transit, so a third party cannot read the file while it is being uploaded or returned. The platform should also encrypt data at rest if it is held, including files, extracted text and review results.

Encryption matters, but it does not answer every confidentiality question. A report can be encrypted while stored for longer than necessary. It can be encrypted yet available to more people than it should be. It can also be processed securely but then used for purposes that were not apparent when the file was uploaded.

Ask for a plain-English explanation of the full data flow. A credible answer should set out whether the original document is retained, where any temporary processing occurs, how long the data remains available, and how deletion works. If a supplier cannot explain this without resorting to vague assurances, that is a concern in itself.

For valuation work, the sensible default is data minimisation. The platform should process only what is needed to perform the requested review, retain it only for the agreed period, and remove it in a controlled way.

Storage is only one part of confidentiality

A useful distinction is often missed. Secure storage and restricted use are separate commitments.

Consider a draft report on a mixed-use property. It may include a confidential passing rent, a tenant covenant comment, lease break dates, an assumed market rent and a valuation figure of £2,750,000. You may be comfortable with a system reading those details to flag that the conclusion says £2,700,000. You may not be comfortable with the same material being retained indefinitely or used to train a general-purpose AI model.

That is why the model-training question deserves a direct answer. Some AI services use customer inputs to improve their models unless the customer opts out or selects a particular enterprise arrangement. For professional valuation work, the better position is straightforward: report data should not be used to train models.

This is not an objection to AI. It is a question of control. The surveyor and their firm decide how confidential instruction material is used. The software provider should not make that decision by default.

What to ask before uploading a report

A short supplier review can prevent misunderstandings later. The answers should be documented, rather than limited to a sales conversation or a broad privacy statement.

Ask these questions:

  • Is the report encrypted in transit and at rest?
  • Is the original file stored, and if so, for how long?
  • Are extracted figures, text and audit findings retained separately from the document?
  • Who can access report data, including support staff and technical administrators?
  • Is access restricted by role and recorded in audit logs?
  • Is any report data used for AI model training, product development or testing?
  • Where is the data processed and stored, and are any third-party processors involved?
  • How are deletion requests handled, including backups and temporary files?
  • What happens if a security incident affects customer data?

The purpose is not to turn a valuation director into an information-security specialist. It is to establish whether the provider understands the professional nature of the material being handled. Clear answers also give a firm a sensible basis for its own internal policy on using review tools.

Access controls matter as much as encryption

A securely stored report should not be visible to everyone at the supplier, or to every user at your own firm. Access needs to follow the practical reality of valuation work.

At firm level, that may mean each user has their own account, permissions are limited to the relevant team, and former staff can be removed promptly. For a lender-side review function or panel manager, it may mean clear separation between instructions, firms and reviewer roles.

At provider level, access should be limited to authorised personnel with a genuine operational need. There will sometimes be a legitimate reason for support access, for example when a user asks for help with a processing issue. Even then, the process should be controlled and traceable, not informal.

It is worth asking whether access events are logged. If a report is opened for support, a record of who accessed it and why is more useful than a general promise that staff take confidentiality seriously.

Retention should fit the purpose

Retention is a commercial and professional decision as well as a technical one. A valuation firm may want completed review results available for a short period so a valuer can revisit a finding or demonstrate that a draft was reviewed before issue. Another firm may require deletion shortly after the report leaves its systems.

There is no single period that suits every instruction. The key is that it is intentional. A platform should allow the firm to understand and control the retention position, rather than leaving reports on an account indefinitely because no one has considered the question.

It is also sensible to distinguish between the report itself and the review output. A finding such as "market rent stated as £185,000 per annum in the narrative and £158,000 per annum in the calculation" may be useful to retain briefly. That does not automatically mean the full report needs to remain available for the same length of time.

Backups require the same clarity. Deleted files may persist in protected backup systems for a limited operational period. That can be reasonable, provided it is explained and handled under a defined deletion process rather than treated as an exception no one can account for.

Security supports, but does not replace, professional judgement

A secure review environment protects confidentiality. It does not alter the valuer's responsibility for the opinion reached or the report issued.

The practical value of an AI-assisted review is that it can read a report as one document, checking repeated figures and related statements at speed. It may flag that a comparable is described as 925 sq m in one section and 952 sq m in another, or that a yield used in a calculation does not match the yield stated in the valuation rationale. The valuer then considers whether there is an error, an explanation, or a reason the apparent inconsistency is appropriate.

That division of work matters. Software can draw attention to points that deserve another look, especially when a report has been amended under time pressure. It cannot decide whether the comparable evidence is sufficient, whether an assumption is reasonable, or whether the valuation conclusion is professionally supportable.

WriteUp is designed around that principle. It provides encrypted private processing, does not store report data or use it for model training, and presents findings for the surveyor to assess. The tool is a second pair of eyes before the report leaves your desk, not a substitute for the valuer signing it.

A sensible standard for your firm

When assessing any AI review service, look for specific controls rather than broad claims. You should be able to identify the encryption approach, retention position, access model, processing location, subcontractors and model-training policy. You should also know who within your firm is permitted to upload reports and what clients or lender instructions require.

The same discipline applied to comparable evidence should apply here. Do not rely on a headline. Read the detail, ask where an answer is unclear, and keep a record of the position reached.

A well-designed review tool should reduce the time spent checking repetitive detail without asking you to give up control of confidential report data. That is the balance worth insisting on: useful scrutiny of the draft, with the report and the professional judgement behind it remaining firmly in the hands of the valuer.