Trust & Security

Security you can hand to your compliance team.

DeferAlly protects sensitive exchange, financial and client data with industry-standard controls. While our SOC 2 audit is underway, our program is mapped to the NIST Cybersecurity Framework 2.0 — and everything your vendor review needs is right here.

SOC 2 readiness in progress Mapped to NIST CSF 2.0 Industry-standard encryption Least-privilege access

How we protect your data

The controls that matter most to an enterprise security reviewer — summarized in plain language.

Encryption

Industry-standard encryption protects data in transit and at rest. All access to the platform is over HTTPS.

Access control

Role-based access with least-privilege defaults. Passwords are securely hashed (bcrypt); invited users are forced to set their own on first login. MFA & SSO are on the near-term roadmap.

Hosting

Runs on reputable managed cloud infrastructure (AWS/GCP-backed) in U.S. regions, with logical tenant isolation per firm.

Data segregation

Multi-tenant architecture keeps each firm's exchanges, clients and documents scoped to that firm only.

Backups & recovery

Automated backups of the primary datastore with documented recovery procedures.

Incident response

A documented process to detect, contain and remediate incidents — and to notify affected customers where appropriate.

System architecture

A modern, layered stack. Sensitive operations happen server-side; the browser never talks to the database directly.

Client (browser)
React SPA served over HTTPS. Auth tokens scoped per session.
API layer
FastAPI over HTTPS. Every request authenticated & authorized by role.
Data layer
Cloud database with encryption at rest and tenant isolation.
Integrations
Payments, email, CRM & AI via vetted subprocessors (see below).

Subprocessors

The third parties we rely on, what they do, and the data they receive. Several receive no client personal data at all.

SubprocessorPurposeData sharedRegion
Managed cloud hosting (AWS/GCP-backed)Application & database hostingAll application data, encrypted at restUnited States
Cloud database (MongoDB)Primary data storeExchange, firm & user recordsUnited States
StripePayment processingBilling details (card data handled by Stripe, PCI-DSS Level 1)United States
ResendTransactional emailRecipient email & message contentUnited States
HubSpotCRM sync (only if a firm connects it)Contact & exchange metadata the firm chooses to syncUnited States
Anthropic (Claude, via Emergent)AI insights & draftingAggregated market data only — no client PIIUnited States
PerplexityRegulatory news searchSearch queries only — no client PIIUnited States
U.S. Census & FREDPublic economic dataNone — read-only public dataUnited States

Vendor security FAQ

The questions procurement and security teams ask most.

Running a security review?

Send us your questionnaire or start with our pre-filled SIG and Mutual NDA. Our team responds fast.

security@deferally.com

This Trust Center describes DeferAlly's security program as a good-faith self-attestation. It is not an audited report or a substitute for one. SOC 2 examination is in progress; controls are mapped to the NIST Cybersecurity Framework 2.0.