Security

Security at every layer.

Tenant isolation. Encryption in transit. Audit logging on every key action. Documented incident response and vulnerability management procedures.

Microsoft AppSource certified·US-resident inference·SOC 2 CC mapped

Authentication and access control

DealPulse uses authenticated user accounts, role-based permissions, and tenant-scoped access checks in the application layer.

  • Authenticated sessions with server-side token management
  • Role-based access control with graduated permission levels
  • User and tenant activity checks before protected-route access

Data protection

DealPulse uses encryption in transit and managed cloud infrastructure for core application storage and processing.

  • HTTPS for application and add-in traffic
  • Managed storage services for databases, files, and transactional systems
  • Dedicated secure storage for Excel add-in authentication

Logging and auditability

DealPulse records authentication, request, and application activity needed for operations, support, and security review.

  • Audit logging for key account and user-management actions
  • Request IDs returned by the backend for support correlation
  • Operational logs available for incident triage and troubleshooting

Infrastructure and operations

The service is hosted on managed cloud infrastructure with supporting managed data services and documented internal operating procedures.

  • Managed cloud infrastructure for application hosting and processing
  • Managed database hosting with backup capabilities
  • Documented internal procedures for incident response, disaster recovery, and vulnerability management

Framework alignment

Mapped against SOC 2 Common Criteria

DealPulse has not yet completed a SOC 2 Type 1 or Type 2 audit. The control families below describe DealPulse's current operating posture and align with the SOC 2 Common Criteria framework. We can share documented procedures with prospective customers under NDA on request.

SOC 2 referenceDealPulse control familyStatus
CC1 — Control environmentDocumented operating procedures, role-based accessPre-audit
CC2 — Communication & infoAudit logging on key actions, request IDs for supportPre-audit
CC3 — Risk assessmentVulnerability management proceduresPre-audit
CC4 — Monitoring activitiesCentralized application loggingPre-audit
CC5 — Control activitiesChange management with code reviewPre-audit
CC6 — Logical & physical accessMFA on admin systems, tenant isolationPre-audit
CC7 — System operationsDocumented incident response proceduresPre-audit
CC8 — Change managementPre-production review on every code changePre-audit
CC9 — Risk mitigationDocumented disaster recovery proceduresPre-audit

"Pre-audit" indicates the control family is in operation but has not been independently attested. DealPulse's full controls register is available to prospective customers under NDA.

Institutional deployments

DealPulse is tenant-isolated by default for every account. Institutional customers with heightened data-isolation or procurement requirements can engage DealPulse on a dedicated deployment with a DealPulse implementation lead.

  • Single-tenant deployment available on request
  • Dedicated implementation lead with CRE acquisitions experience
  • Data-handling practices documented in this security overview
  • Security questionnaires answered on request for prospective customers

Operational requirements

DealPulse's internal operating baseline requires MFA for administrative systems such as code repositories, DNS management, and credential or key stores. Security issues are triaged through internal incident response and vulnerability management procedures before production changes are approved.

Monitoring and incident handling

DealPulse maintains centralized application logging and documented response procedures for authentication issues, application failures, and customer-reported security events. If you need a security point of contact, use our support page or contact support@dealpulsecre.ai.

Related documents

For information about personal data handling, see our privacy policy. For Microsoft Marketplace distribution terms, see our terms of service.

Questions your security review still has?

Bring them to the demo call — or write to support@dealpulsecre.ai.

v1.10.0·Tenant-isolated·US-resident inference·Microsoft AppSource certified·Pre-audit SOC 2 CC mapped