Data Security
Storage, access control, encryption, and compliance documentation
94/100
Security Score
14
Active Controls
3
Data Tiers
Aug 10
Last Audit
Encryption
All documents and database fields containing PII or financial data
All API communication and file transfers
Hardware-backed key storage with automatic rotation
Sensitive financial fields encrypted independently
Access Control
Multi-factor authentication required for all accounts
Role-based access: Admin, Manager, Analyst, Viewer
Users only access deals they are assigned to
100 req/min per user, 1000 req/min per org
Data Classification
Market research, published reports, general platform content
Deal summaries, aggregate analytics, team communications
Financial models, rent rolls, appraisals, investor PII, legal docs
Monitoring & Audit
All data access, modifications, and exports tracked with user/timestamp
Unusual access patterns trigger alerts to security admin
Quarterly compliance reporting and evidence collection
Configurable retention: 1yr min, 7yr max, with secure deletion
Role-Based Access Control (RBAC)
Infrastructure Security
- Cloudflare R2 with server-side encryption
- Bucket-level access policies
- Geographic data residency controls
- Versioning enabled for audit recovery
- PostgreSQL with SSL-only connections
- Row-level security policies
- Automated daily encrypted backups
- Point-in-time recovery (30 days)
- Cloudflare WAF and DDoS protection
- API gateway with request validation
- IP allowlisting for admin endpoints
- VPN required for database access
- SSO integration (SAML/OIDC)
- Multi-factor authentication enforced
- Session timeout: 30 min inactive
- Password policy: 12+ chars, complexity