M&A data is sensitive. People go to prison for leaking it. We built Dealspace with security as the foundation, not an afterthought.
Self-Assessed · Type II in progress
Validated encryption
Compliant processing
Certified ISMS
We use the same encryption standards required by US federal agencies. Your deal data is encrypted with AES-256-GCM using FIPS 140-3 validated cryptographic modules.
Each deal has its own encryption key derived from a master key. One deal's compromise does not affect others.
All data encrypted before it touches disk. File content, metadata, comments — everything.
TLS 1.3 for all connections. Certificate pinning for mobile apps. No data travels unencrypted.
Every document is watermarked with the viewer's identity at serve time. If a document leaks, you know exactly who leaked it.
Watermark includes user email, organization, timestamp, and deal ID.
PDF, Word, Excel, images, video. Protection adapts to the format.
Control watermark content, position, and visibility.
Multiple layers of protection. Every access decision goes through the same choke point. No exceptions.
SAML 2.0 and OIDC support. Integrate with your existing identity provider. Enforce your organization's auth policies.
TOTP, hardware keys (FIDO2), SMS backup. MFA required for all access, no exceptions.
Workstream-level permissions. IB, Seller, Buyer roles with configurable scopes. Least privilege by default.
Short-lived tokens. Single active session per user. Immediate revocation on access changes.
Restrict access by IP range. Corporate network only, or specific buyer locations.
Disable downloads entirely, or allow view-only access. Configurable per document or project-wide.
Every action is logged. Access grants, file views, downloads, status changes — all recorded with actor, timestamp, and IP address.
Dedicated infrastructure, redundant storage, continuous monitoring. Your deal data deserves nothing less.
Talk to our security team. We are happy to answer technical questions and provide documentation.