Home/Security
Security at DEALWISE
How we protect the most sensitive information an investment office holds: architecture, encryption, access, audit, resilience and incident response.
DEALWISE holds what an institution is buying, at what price, on whose recommendation and with what risks attached. Security shapes every layer of the product and every stage of how we build it.
Our security programme
DEALWISE holds some of the most sensitive information an institution owns: what it is buying, at what price, on whose recommendation and with what risks attached. Our security programme is built on that premise.
The programme is designed around ISO 27001 for information security management and ISO 31000 for risk management, with control objectives mapped to the COSO internal control framework. It is owned by our security function, reviewed by management on a quarterly cycle, and covers people, process and technology rather than technology alone.
Architecture and tenancy
- Logical isolation. Every client operates in a dedicated, logically isolated tenant. Tenant identity is enforced at the data layer, not only in the application.
- Deployment choice. DEALWISE Cloud in a region you select, deployment into your own cloud tenancy, or fully on-premises, so data residency and network controls follow your policy.
- Segregated environments. Development, test and production are separate, with no production data used in lower environments.
- Defence in depth. Network segmentation, web application firewalling, rate limiting and DDoS protection sit in front of the application tier.
Encryption and key management
- In transit: TLS 1.2 or above with modern cipher suites and HTTP Strict Transport Security; older protocols are disabled.
- At rest: AES-256 for databases, document storage and backups.
- Key management: keys held in a managed key service with rotation, split duties and audited access. Customer-managed keys are supported for private tenancy and on-premises deployments.
- Secrets: application secrets are held in a vault, never in source control or configuration files.
Identity and access control
- Single sign-on through your identity provider (SAML 2.0 / OpenID Connect), with SCIM provisioning and automatic de-provisioning on leaver events.
- Multi-factor authentication enforced for all administrative access and available for all users; configurable password policy where local accounts are used.
- Role-based permissions granted to roles, roles to user groups, and groups to people, with deal-level restriction for sensitive live transactions and time-bound, approved access requests.
- Segregation of duties enforced by the Delegation of Authority matrix: requesters cannot approve their own transactions.
- Least privilege for our own staff. Access to a client environment requires a business justification, is approved, time-boxed, logged, and reviewed at least quarterly.
Logging, monitoring and audit trail
Every create, change, approval, deletion and document access event is written to an immutable audit log recording who acted, when, from what value to what value, and under whose authority. Logs are tamper-evident, filterable and exportable, so most audit evidence requests are answered with a standard report.
Security telemetry covering authentication events, permission changes and privileged actions can be forwarded to your own SIEM. We maintain 24×7 alerting on anomalous authentication, privilege escalation and data egress patterns.
Secure development
- Secure coding standards, mandatory peer review and segregation between the author and the approver of a change.
- Automated static analysis, dependency and container scanning in the build pipeline; builds fail on high-severity findings.
- Threat modelling for new features that change trust boundaries or handle new data classes.
- Change management with documented approval, staged rollout and a tested rollback path.
- Annual independent penetration testing by a qualified third party, with findings tracked to closure and an executive summary available to clients under NDA.
Resilience and continuity
- Backups: encrypted, taken continuously with point-in-time recovery, replicated across availability zones and retained per the agreed schedule.
- Recovery objectives: a target RPO of 15 minutes and RTO of 4 hours for DEALWISE Cloud, confirmed contractually per client.
- Testing: restores are tested regularly and disaster recovery is exercised at least annually; results are documented.
- Availability: a 99.9% monthly uptime target for DEALWISE Cloud, excluding scheduled maintenance notified in advance.
Incident response
We operate a documented incident response plan with defined severity levels, named responders and communication paths. In the event of a confirmed security incident affecting your data we will:
- contain and investigate immediately, preserving forensic evidence;
- notify affected clients without undue delay and within 72 hours of confirmation, with the facts known at that time;
- provide regular updates through resolution, and a written post-incident review including root cause and corrective actions.
The plan is tested through tabletop exercises at least annually.
People and suppliers
- Background screening appropriate to role and jurisdiction, and confidentiality obligations for all personnel.
- Security awareness training at onboarding and annually, with targeted training for engineering and support.
- A formal supplier assurance process: sub-processors are assessed before engagement, bound by written contract and reviewed periodically. Our sub-processor register is available on request.
- Documented joiner, mover and leaver procedures with same-day revocation of access on departure.
Data protection
We support your obligations as controller: data processing agreements including Standard Contractual Clauses where relevant, documented retention and deletion, assistance with data subject requests, and return or verified deletion of your data on termination. See the Privacy Notice for how we handle personal data in our own capacity.
Responsible disclosure
Found a vulnerability? Please report it to [email protected] with enough detail to reproduce the issue. We acknowledge reports within two business days, keep you updated, and will credit you publicly if you would like us to.
We ask that you give us reasonable time to remediate before disclosure, avoid accessing or modifying data that is not yours, and do not run denial-of-service or social engineering tests against our systems or our clients. We will not pursue legal action against researchers who act in good faith within these guidelines.
Assurance and documentation
For procurement, vendor risk and internal audit reviews we can provide, under NDA where appropriate:
- a security architecture overview and data flow diagrams;
- our control mapping against ISO 27001, ISO 31000 and COSO;
- the executive summary of the latest independent penetration test;
- business continuity and disaster recovery documentation with test results;
- the sub-processor register and standard data processing agreement;
- completed responses to your own security questionnaire.
Request the pack from [email protected].
This document is provided for information. It is a template prepared for the DEALWISE website and should be reviewed by qualified legal counsel in your jurisdiction before it is relied upon commercially. Questions may be sent to [email protected].