Bank-grade security.
Built for fund managers.
Your deal data is some of the most sensitive information your fund holds. We treat it that way — from infrastructure to access control to compliance.
How we protect your data
Security is not a feature — it's the foundation every other feature is built on.
Encryption
End-to-end encrypted storage
All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys are managed per-workspace and rotated automatically — no shared keys across funds.
- AES-256 at rest
- TLS 1.3 in transit
- Per-workspace key isolation
- Automatic key rotation
Access Control
Role-based access with full audit trails
Granular permissions at the workspace, role, and resource level. Every action — reads, writes, exports — is logged with user identity, timestamp, and IP address.
- Granular role permissions
- Workspace isolation
- Full immutable audit log
- Session timeout controls
Infrastructure
Zero single points of failure
Hosted on AWS with multi-region redundancy. Automated backups every 6 hours with point-in-time recovery. All datastores replicated across availability zones.
- AWS multi-region
- Backups every 6 hours
- Point-in-time recovery
- DDoS protection
Compliance
SOC 2 Type II and GDPR certified
Independently audited annually for SOC 2 Type II. GDPR-compliant data processing with documented DPAs. EU data residency available on Enterprise plans.
- SOC 2 Type II (annual audit)
- GDPR / CCPA compliant
- EU data residency (Enterprise)
- Data processing agreements
Monitoring
24/7 anomaly detection
Real-time monitoring for unusual access patterns, authentication spikes, and exfiltration indicators. Automated alerts fire within minutes of detection.
- 24/7 anomaly detection
- Failed auth monitoring
- Rate limiting + throttling
- Automated alert escalation
Incident Response
4-hour SLA for critical incidents
Documented incident response plan with named owners for each severity level. Enterprise customers receive a direct communication channel and post-incident report within 72 hours.
- 4h critical response SLA
- Named incident owners
- Post-incident reports (72h)
- Enterprise direct channel
Responsible Disclosure
Found a vulnerability?
We take security reports seriously and respond within 48 hours. Please disclose responsibly — we do not pursue legal action against good-faith researchers following our disclosure guidelines.
security@deelsignal.comBe among the first founding funds
Prefer a walkthrough? Book a 20-min demo instead →