Everything institutional buyers need to evaluate DealSafi’s security posture, compliance certifications, and data handling practices. If it is not here, email trust@dealsafi.ai.
We provide 30 days’ notice of any new sub-processor addition. To object to a new sub-processor, contact legal@dealsafi.ai.
DealSafi operates a responsible disclosure programme. If you discover a security vulnerability in our platform or website, we ask that you report it to us before making it public.
We commit to: acknowledging your report within 2 business days; keeping you informed of our progress; not taking legal action against researchers acting in good faith; and giving credit in our security acknowledgements (if desired).
Please do not access, modify, or delete data that does not belong to you. Do not perform actions that could affect service availability.
Report a vulnerabilityAvailable under NDA to customers and qualified prospects. Expected Q4 2025.
Scope, methodology, and finding summary. Available under NDA. Full report available to Enterprise and Portfolio customers.
GDPR Art. 28 DPA including SCCs Module 2, sub-processor list, and technical measures schedule. Available immediately.
CAIQ, SIG Lite, and custom questionnaires completed within 5 business days for qualified prospects.
Datadog monitors all systems 24/7. Anomaly detection alerts the on-call engineer within minutes. All alerts are logged to an incident record.
Target: < 15 minutes detection
Affected systems isolated. Customer notification within 24 hours of confirmed breach. GDPR supervisory authority notification within 72 hours if required.
GDPR Art. 33 compliant
Systems restored from clean backups. Post-incident report shared with affected customers within 14 days. Root cause and remediation documented.
Full transparency policy
Our trust team responds to security enquiries within one business day. We complete standard security questionnaires within five business days.