DeferAlly's security program mapped to the six functions of the NIST Cybersecurity Framework (CSF) 2.0. This is a good-faith self-attestation to support enterprise vendor reviews while our SOC 2 examination is in progress — not an audited report.
The organization's cybersecurity risk management strategy, expectations and policy are established and monitored.
Mission, stakeholders (QIs, family offices, attorneys) and legal/regulatory obligations for handling 1031 exchange and financial data are documented.
Risk appetite and priorities defined; formal risk register being matured as part of SOC 2 readiness.
Security ownership assigned to leadership; least-privilege access defined by role across the platform.
Acceptable use, access, encryption and incident policies documented; expanding into a full policy library.
Subprocessors inventoried with purpose and data shared (see Trust Center); reviewed before onboarding.
Current cybersecurity risks to systems, people, assets, data and capabilities are understood.
Application, data stores and third-party services are inventoried, including where data lives (U.S. cloud regions).
Threats, vulnerabilities and dependency risks are reviewed periodically; formal cadence being standardized.
Findings from reviews and incidents feed back into the roadmap and control improvements.
Safeguards to manage the organization's cybersecurity risks are used.
Role-based access, least privilege, bcrypt-hashed passwords, scoped session tokens and forced password resets for invited users. MFA/SSO on the near-term roadmap.
Industry-standard encryption for data in transit and at rest; multi-tenant isolation keeps each firm's data separate.
Managed cloud hosting (AWS/GCP-backed); server-side validation; the browser never talks to the database directly.
Security expectations communicated to the team; formal recurring training being introduced.
Automated backups and documented recovery procedures protect data availability.
Possible cybersecurity attacks and compromises are found and analyzed.
Application and platform logs are monitored; dependency and vulnerability monitoring in place, expanding coverage.
Suspicious activity is investigated and triaged; formal alerting thresholds being tuned.
Actions regarding a detected cybersecurity incident are taken.
Documented incident-response process to detect, contain, investigate and remediate incidents.
Incidents are analyzed for root cause; affected customers are notified where appropriate. Report to security@deferally.com.
Containment and eradication steps are executed to limit impact.
Assets and operations affected by a cybersecurity incident are restored.
Automated backups and documented recovery procedures enable restoration of service and data.
Stakeholders and affected customers are kept informed during and after recovery.
Self-attestation as of September 2026. Questions: security@deferally.com. This mapping is not a substitute for an independent SOC 2 or ISO 27001 audit.