Security
Security at every layer.
Tenant isolation. Encryption in transit. Audit logging on every key action. Documented incident response and vulnerability management procedures.
Microsoft AppSource certified·US-resident inference·SOC 2 CC mapped
Authentication and access control
DealPulse uses authenticated user accounts, role-based permissions, and tenant-scoped access checks in the application layer.
- •Authenticated sessions with server-side token management
- •Role-based access control with graduated permission levels
- •User and tenant activity checks before protected-route access
Data protection
DealPulse uses encryption in transit and managed cloud infrastructure for core application storage and processing.
- •HTTPS for application and add-in traffic
- •Managed storage services for databases, files, and transactional systems
- •Dedicated secure storage for Excel add-in authentication
Logging and auditability
DealPulse records authentication, request, and application activity needed for operations, support, and security review.
- •Audit logging for key account and user-management actions
- •Request IDs returned by the backend for support correlation
- •Operational logs available for incident triage and troubleshooting
Infrastructure and operations
The service is hosted on managed cloud infrastructure with supporting managed data services and documented internal operating procedures.
- •Managed cloud infrastructure for application hosting and processing
- •Managed database hosting with backup capabilities
- •Documented internal procedures for incident response, disaster recovery, and vulnerability management
Framework alignment
Mapped against SOC 2 Common Criteria
DealPulse has not yet completed a SOC 2 Type 1 or Type 2 audit. The control families below describe DealPulse's current operating posture and align with the SOC 2 Common Criteria framework. We can share documented procedures with prospective customers under NDA on request.
| SOC 2 reference | DealPulse control family | Status |
|---|---|---|
| CC1 — Control environment | Documented operating procedures, role-based access | Pre-audit |
| CC2 — Communication & info | Audit logging on key actions, request IDs for support | Pre-audit |
| CC3 — Risk assessment | Vulnerability management procedures | Pre-audit |
| CC4 — Monitoring activities | Centralized application logging | Pre-audit |
| CC5 — Control activities | Change management with code review | Pre-audit |
| CC6 — Logical & physical access | MFA on admin systems, tenant isolation | Pre-audit |
| CC7 — System operations | Documented incident response procedures | Pre-audit |
| CC8 — Change management | Pre-production review on every code change | Pre-audit |
| CC9 — Risk mitigation | Documented disaster recovery procedures | Pre-audit |
"Pre-audit" indicates the control family is in operation but has not been independently attested. DealPulse's full controls register is available to prospective customers under NDA.
Institutional deployments
DealPulse is tenant-isolated by default for every account. Institutional customers with heightened data-isolation or procurement requirements can engage DealPulse on a dedicated deployment with a DealPulse implementation lead.
- Single-tenant deployment available on request
- Dedicated implementation lead with CRE acquisitions experience
- Data-handling practices documented in this security overview
- Security questionnaires answered on request for prospective customers
Operational requirements
DealPulse's internal operating baseline requires MFA for administrative systems such as code repositories, DNS management, and credential or key stores. Security issues are triaged through internal incident response and vulnerability management procedures before production changes are approved.
Monitoring and incident handling
DealPulse maintains centralized application logging and documented response procedures for authentication issues, application failures, and customer-reported security events. If you need a security point of contact, use our support page or contact support@dealpulsecre.ai.
Related documents
For information about personal data handling, see our privacy policy. For Microsoft Marketplace distribution terms, see our terms of service.
Questions your security review still has?
Bring them to the demo call — or write to support@dealpulsecre.ai.