Back to Trust Center
DeferAlly
Security Questionnaire (SIG-Lite)

Standardized Security Assessment

A pre-filled, SIG-style questionnaire covering the domains enterprise procurement and security teams review. Provided in lieu of a SOC 2 Type 1 for early-stage evaluations. For a specific questionnaire (SIG Core, CAIQ, custom), email security@deferally.com and we'll complete yours directly.

A. Company & Program

Company legal name
DeferAlly, Inc. (Delaware corporation)
Product
DeferAlly — a 1031 exchange management platform for qualified intermediaries, family offices, attorneys and wealth managers.
Do you have a SOC 2 / ISO 27001 report?
SOC 2 examination is in progress. Controls are currently self-attested and mapped to NIST CSF 2.0 (see our published control mapping).
Is there a documented information security program?
Yes. Policies cover access control, encryption, acceptable use and incident response; the library is expanding as part of SOC 2 readiness.
Security point of contact
security@deferally.com

B. Access Control & Authentication

How are user passwords stored?
Securely hashed with bcrypt. Plaintext passwords are never stored.
Is role-based access control (RBAC) enforced?
Yes. Access follows least privilege; firm users can only access their own firm's data.
Is MFA available?
MFA and SSO are on the near-term roadmap. Today accounts use hashed passwords, scoped session tokens and forced password resets for invited users.
How are sessions managed?
Authenticated sessions use scoped tokens; every API request is authenticated and authorized by role.
How is administrative access controlled?
Administrative access is limited to authorized personnel on a need-to-know basis.

C. Data Protection & Encryption

Is data encrypted in transit?
Yes — industry-standard encryption; all access to the platform is over HTTPS.
Is data encrypted at rest?
Yes — industry-standard encryption at the data layer.
Is customer data logically separated?
Yes. The multi-tenant architecture scopes each firm's exchanges, clients and documents to that firm.
Is cardholder data handled directly?
No. Payment card data is processed by Stripe (PCI-DSS Level 1). DeferAlly does not store full card numbers.
Is customer data used to train AI models?
No. AI features receive only aggregated, non-PII market data.

D. Hosting & Infrastructure

Where is the application hosted?
On reputable managed cloud infrastructure (AWS/GCP-backed) in United States regions.
Where is customer data stored?
In a cloud database (MongoDB) within U.S. regions, encrypted at rest.
Is the environment multi-tenant or single-tenant?
Multi-tenant with logical isolation per firm.
Are development and production environments separated?
Yes.

E. Application Security

Is input validated server-side?
Yes. Sensitive operations are performed server-side; the browser never connects to the database directly.
How are dependencies and vulnerabilities managed?
Dependencies are kept up to date and monitored for known vulnerabilities; periodic security reviews are performed.
Do you perform penetration testing?
Periodic security reviews are conducted; formal third-party penetration testing is part of SOC 2 readiness.
Is there a responsible disclosure process?
Yes — report to security@deferally.com.

F. Business Continuity & Backups

Are backups performed?
Yes — automated backups of the primary datastore.
Is there a documented recovery procedure?
Yes, enabling restoration of service and data after a failure.
Is there a business continuity / disaster recovery plan?
Yes, documented and maintained; recovery objectives are being formalized.

G. Incident Response

Is there a documented incident-response plan?
Yes — to detect, contain, investigate and remediate incidents.
Will affected customers be notified of a breach?
Yes, where appropriate and in line with applicable law.
Are incidents analyzed for root cause?
Yes; findings drive control improvements.

H. Vendor / Subprocessor Management

Do you use subprocessors?
Yes. A current list (purpose and data shared) is published in our Trust Center. Several AI/data providers receive no client PII.
Are subprocessors reviewed before onboarding?
Yes.
Do you sell customer data?
No. Customer data is never sold.

I. Privacy & Data Lifecycle

What is your data retention policy?
Data is retained for the life of the account and deleted or returned on request or termination, subject to legal requirements.
Can a customer request data export or deletion?
Yes — contact security@deferally.com or support@deferally.com.
Is there a published Privacy Policy?
Yes, available at /privacy.

Completed by (DeferAlly)

Name / Title

Date

Reviewed by (Counterparty)

Name / Title

Date

Good-faith self-attestation as of September 2026. Not an audited report. SOC 2 examination in progress; controls mapped to NIST CSF 2.0.