DeferAlly protects sensitive exchange, financial and client data with industry-standard controls. While our SOC 2 audit is underway, our program is mapped to the NIST Cybersecurity Framework 2.0 — and everything your vendor review needs is right here.
SOC 2 readiness in progress Mapped to NIST CSF 2.0 Industry-standard encryption Least-privilege access
The controls that matter most to an enterprise security reviewer — summarized in plain language.
Encryption
Industry-standard encryption protects data in transit and at rest. All access to the platform is over HTTPS.
Access control
Role-based access with least-privilege defaults. Passwords are securely hashed (bcrypt); invited users are forced to set their own on first login. MFA & SSO are on the near-term roadmap.
Hosting
Runs on reputable managed cloud infrastructure (AWS/GCP-backed) in U.S. regions, with logical tenant isolation per firm.
Data segregation
Multi-tenant architecture keeps each firm's exchanges, clients and documents scoped to that firm only.
Backups & recovery
Automated backups of the primary datastore with documented recovery procedures.
Incident response
A documented process to detect, contain and remediate incidents — and to notify affected customers where appropriate.
System architecture
A modern, layered stack. Sensitive operations happen server-side; the browser never talks to the database directly.
Client (browser)
React SPA served over HTTPS. Auth tokens scoped per session.
API layer
FastAPI over HTTPS. Every request authenticated & authorized by role.
Data layer
Cloud database with encryption at rest and tenant isolation.
Integrations
Payments, email, CRM & AI via vetted subprocessors (see below).
Subprocessors
The third parties we rely on, what they do, and the data they receive. Several receive no client personal data at all.
Subprocessor
Purpose
Data shared
Region
Managed cloud hosting (AWS/GCP-backed)
Application & database hosting
All application data, encrypted at rest
United States
Cloud database (MongoDB)
Primary data store
Exchange, firm & user records
United States
Stripe
Payment processing
Billing details (card data handled by Stripe, PCI-DSS Level 1)
United States
Resend
Transactional email
Recipient email & message content
United States
HubSpot
CRM sync (only if a firm connects it)
Contact & exchange metadata the firm chooses to sync
United States
Anthropic (Claude, via Emergent)
AI insights & drafting
Aggregated market data only — no client PII
United States
Perplexity
Regulatory news search
Search queries only — no client PII
United States
U.S. Census & FRED
Public economic data
None — read-only public data
United States
Vendor security FAQ
The questions procurement and security teams ask most.
Running a security review?
Send us your questionnaire or start with our pre-filled SIG and Mutual NDA. Our team responds fast.
This Trust Center describes DeferAlly's security program as a good-faith self-attestation. It is not an audited report or a substitute for one. SOC 2 examination is in progress; controls are mapped to the NIST Cybersecurity Framework 2.0.