Initializing workspace...

Security

Security you can check.
Built for fund managers.

Your deal data is some of the most sensitive information your fund holds. We treat it that way — from infrastructure to access control to compliance.

Overview

How we protect your data.

Security is not a feature — it's the foundation every other feature is built on.

Compliance status

  • SOC 2 Type II audit in progress
  • GDPR- and CCPA-aligned
  • DPA available
  • Encrypted in transit and at rest
  • AES-256-GCM for stored credentials
  • Published subprocessor list
01

Encryption

Encrypted in transit and at rest

The platform is served only over HTTPS. The database is encrypted at rest. Stored credentials — OAuth tokens, API keys, SMTP passwords, SSO secrets — are encrypted again at field level with AES-256-GCM before they are written, under a key held outside the database.

  • TLS in transit
  • Database encrypted at rest
  • AES-256-GCM field encryption for credentials
  • Encryption key held outside the database
02

Access Control

Role-based access with an audit trail

Each workspace's records are scoped to that workspace in the data-access rules, not just the interface. Within a workspace, permissions follow the member's role. Record changes, exports and LP document views are written to an audit log with the acting user, time and, where available, IP address — and audit entries cannot be edited or deleted through the API.

  • Role-based permissions
  • Workspace isolation
  • Append-only audit log (via the API)
  • SAML SSO on every plan
03

Infrastructure

Managed, replicated infrastructure

The platform runs on managed cloud infrastructure, served only over HTTPS. The database runs as a replicated cluster, so losing one machine loses no data. Ask us for the current backup schedule and recovery targets — we will put them in writing rather than on a banner.

  • Managed hosting
  • Replicated database
  • Encrypted at rest
  • HTTPS only
  • DDoS protection
04

Compliance

SOC 2 Type II audit in progress

A SOC 2 Type II audit is in progress; we do not hold a report today, and this page will say so when we do. Our data processing is aligned with GDPR and CCPA, and a Data Processing Agreement — GDPR Article 28, with Standard Contractual Clauses for international transfers — is available. EU data residency available on Enterprise plans.

  • SOC 2 Type II audit in progress
  • GDPR- and CCPA-aligned data processing
  • DPA available
  • EU data residency (Enterprise)
05

Monitoring

Rate limits, lockouts and failed-action tracking

Sign-in, sign-up and public endpoints are rate limited. An account is locked for ten minutes after five consecutive failed sign-ins. Failed actions are recorded in the workspace audit log, where admins can review them.

locked · 10 min
  • Rate limiting + throttling
  • Lockout after 5 failed sign-ins
  • Failed actions in the audit log
  • Admin-visible audit trail
06

Incident Response

Breach notification under the DPA

Security reports go to security@deelsignal.com. Customers who sign our DPA are notified of a personal data breach affecting their data without undue delay, with what is known about its scope and the steps taken.

  • security@deelsignal.com
  • Breach notification without undue delay (DPA)
  • Audit log available for investigation

Responsible Disclosure

We take security reports seriously and respond within 48 hours. Please disclose responsibly — we do not pursue legal action against good-faith researchers following our disclosure guidelines.

security@deelsignal.comReport a vulnerability

Ready to see it for yourself?

Talk to us about how DeelSignal keeps your fund's data secure, workspace by workspace.