Data Security

Storage, access control, encryption, and compliance documentation

94/100

Security Score

14

Active Controls

3

Data Tiers

Aug 10

Last Audit

Encryption

At-Rest EncryptionActive
AES-256-GCM

All documents and database fields containing PII or financial data

In-Transit EncryptionActive
TLS 1.3

All API communication and file transfers

Key ManagementActive
AWS KMS / CF

Hardware-backed key storage with automatic rotation

Field-Level EncryptionActive
AES-256

Sensitive financial fields encrypted independently

Access Control

AuthenticationActive
JWT + MFA

Multi-factor authentication required for all accounts

AuthorizationActive
RBAC

Role-based access: Admin, Manager, Analyst, Viewer

Row-Level SecurityActive
PostgreSQL RLS

Users only access deals they are assigned to

API Rate LimitingActive
Token Bucket

100 req/min per user, 1000 req/min per org

Data Classification

PublicActive
Tier 1

Market research, published reports, general platform content

InternalActive
Tier 2

Deal summaries, aggregate analytics, team communications

PrivateActive
Tier 3

Financial models, rent rolls, appraisals, investor PII, legal docs

Monitoring & Audit

Audit TrailActive
Event Log

All data access, modifications, and exports tracked with user/timestamp

Anomaly DetectionPlanned
ML-based

Unusual access patterns trigger alerts to security admin

Compliance ReportsIn Progress
SOC 2

Quarterly compliance reporting and evidence collection

Data RetentionActive
Policy

Configurable retention: 1yr min, 7yr max, with secure deletion

Role-Based Access Control (RBAC)

Admin
2 users
Full platform accessUser managementSecurity settingsAudit logsAPI key management
Manager
5 users
Deal CRUDDocument managementUnderwritingAnalyticsAI AssistantTeam view
Analyst
12 users
Deal read/writeDocument uploadUnderwritingAnalytics readAI Assistant
Viewer
45 users
Deal read-onlyDocument read-onlyAnalytics read-only
External
92 users
Shared deal view onlyDownload permitted docsNo AI access

Infrastructure Security

Cloud Storage
  • Cloudflare R2 with server-side encryption
  • Bucket-level access policies
  • Geographic data residency controls
  • Versioning enabled for audit recovery
Database
  • PostgreSQL with SSL-only connections
  • Row-level security policies
  • Automated daily encrypted backups
  • Point-in-time recovery (30 days)
Network
  • Cloudflare WAF and DDoS protection
  • API gateway with request validation
  • IP allowlisting for admin endpoints
  • VPN required for database access
Identity
  • SSO integration (SAML/OIDC)
  • Multi-factor authentication enforced
  • Session timeout: 30 min inactive
  • Password policy: 12+ chars, complexity