Back to Trust Center
DeferAlly
NIST CSF 2.0 Control Mapping

Cybersecurity Framework Self-Assessment

DeferAlly's security program mapped to the six functions of the NIST Cybersecurity Framework (CSF) 2.0. This is a good-faith self-attestation to support enterprise vendor reviews while our SOC 2 examination is in progress — not an audited report.

In placePartialRoadmap

GV · Govern

The organization's cybersecurity risk management strategy, expectations and policy are established and monitored.

Organizational Context (GV.OC)In place

Mission, stakeholders (QIs, family offices, attorneys) and legal/regulatory obligations for handling 1031 exchange and financial data are documented.

Risk Management Strategy (GV.RM)Partial

Risk appetite and priorities defined; formal risk register being matured as part of SOC 2 readiness.

Roles & Responsibilities (GV.RR)In place

Security ownership assigned to leadership; least-privilege access defined by role across the platform.

Policy (GV.PO)Partial

Acceptable use, access, encryption and incident policies documented; expanding into a full policy library.

Oversight & Supply Chain (GV.OV / GV.SC)In place

Subprocessors inventoried with purpose and data shared (see Trust Center); reviewed before onboarding.

ID · Identify

Current cybersecurity risks to systems, people, assets, data and capabilities are understood.

Asset Management (ID.AM)In place

Application, data stores and third-party services are inventoried, including where data lives (U.S. cloud regions).

Risk Assessment (ID.RA)Partial

Threats, vulnerabilities and dependency risks are reviewed periodically; formal cadence being standardized.

Improvement (ID.IM)In place

Findings from reviews and incidents feed back into the roadmap and control improvements.

PR · Protect

Safeguards to manage the organization's cybersecurity risks are used.

Identity Management & Access Control (PR.AA)Partial

Role-based access, least privilege, bcrypt-hashed passwords, scoped session tokens and forced password resets for invited users. MFA/SSO on the near-term roadmap.

Data Security (PR.DS)In place

Industry-standard encryption for data in transit and at rest; multi-tenant isolation keeps each firm's data separate.

Platform Security (PR.PS)In place

Managed cloud hosting (AWS/GCP-backed); server-side validation; the browser never talks to the database directly.

Awareness & Training (PR.AT)Partial

Security expectations communicated to the team; formal recurring training being introduced.

Technology Resilience (PR.IR)In place

Automated backups and documented recovery procedures protect data availability.

DE · Detect

Possible cybersecurity attacks and compromises are found and analyzed.

Continuous Monitoring (DE.CM)Partial

Application and platform logs are monitored; dependency and vulnerability monitoring in place, expanding coverage.

Adverse Event Analysis (DE.AE)Partial

Suspicious activity is investigated and triaged; formal alerting thresholds being tuned.

RS · Respond

Actions regarding a detected cybersecurity incident are taken.

Incident Management (RS.MA)In place

Documented incident-response process to detect, contain, investigate and remediate incidents.

Incident Analysis & Reporting (RS.AN / RS.CO)In place

Incidents are analyzed for root cause; affected customers are notified where appropriate. Report to security@deferally.com.

Incident Mitigation (RS.MI)In place

Containment and eradication steps are executed to limit impact.

RC · Recover

Assets and operations affected by a cybersecurity incident are restored.

Incident Recovery Plan Execution (RC.RP)In place

Automated backups and documented recovery procedures enable restoration of service and data.

Recovery Communication (RC.CO)In place

Stakeholders and affected customers are kept informed during and after recovery.

Self-attestation as of September 2026. Questions: security@deferally.com. This mapping is not a substitute for an independent SOC 2 or ISO 27001 audit.