Security Overview

(Early Access)

Last updated: October 2025

Data boundaries

We track public, first-party vendor pages (pricing, changelog, docs, integrations, trust).

We do not require CRM or customer-PII access.

Protections

Encryption: TLS in transit; encrypted storage at rest.

Access: role-based access; least-privilege for staff; admin-action logging; periodic access reviews.

Backups: regular backups and restore testing.

Operations

Business-hours support via Slack Connect/email.

Best-effort incident response; we will notify workspace owners without undue delay if a data incident affects them.

Vulnerability reporting

Email security@getdealforge.com. A /.well-known/security.txt file is available.

Compliance

We do not claim SOC 2/ISO certifications yet. A lightweight DPA (with SCCs for transfers) is available on request.

💬Feedback