Trust & Security
Your data is safe.
Enterprise-grade security built into every layer of the Dealgrounds platform.
🔒
Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Database backups are encrypted and stored in geographically distributed, access-controlled facilities.
🛡
Access Controls
Role-based access control (RBAC) with granular permissions. SSO via SAML 2.0 and SCIM provisioning for Enterprise customers. Multi-factor authentication available on all plans.
🔍
Audit Logging
Comprehensive audit trails for all platform actions. Immutable logs track user access, data changes, approval workflows, and administrative actions for full accountability.
🏙
Infrastructure
Hosted on SOC 2 certified cloud infrastructure with redundant systems across multiple availability zones. Automated failover and disaster recovery with RPO under 1 hour.
Data Protection
Dealgrounds takes a defence-in-depth approach to data protection. Your client entertainment data, CRM integrations, and business intelligence are protected by multiple layers of security controls.
- All customer data is logically isolated at the application and database level
- Personally identifiable information (PII) is encrypted at the field level
- Data residency options available for Canadian and EU customers
- Automated data classification and handling policies
- Regular penetration testing by independent third-party firms
Application Security
Security is embedded in our development lifecycle from design through deployment:
- Secure software development lifecycle (SSDLC) with mandatory code reviews
- Automated static analysis (SAST) and dynamic analysis (DAST) scanning
- Dependency vulnerability monitoring with automated patching
- Web application firewall (WAF) with DDoS protection
- API rate limiting and input validation on all endpoints
- Content Security Policy (CSP) headers and XSS protection
Compliance
Dealgrounds maintains compliance with applicable Canadian and international privacy regulations:
- SOC 2 Type II certified (annual audit by independent firm)
- Compliant with Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25)
- Compliant with the Personal Information Protection and Electronic Documents Act (PIPEDA)
- GDPR-ready for European clients
- Annual third-party penetration testing and vulnerability assessments
Incident Response
We maintain a documented incident response plan that includes:
- 24/7 security monitoring and alerting
- Defined escalation procedures with clear ownership
- Notification of affected customers within 72 hours of a confirmed breach
- Post-incident review and remediation documentation
- Regular tabletop exercises to test response readiness
Employee Security
- Background checks for all employees with access to customer data
- Mandatory security awareness training (annual + onboarding)
- Principle of least privilege for all system access
- Endpoint detection and response (EDR) on all company devices
- Confidentiality agreements for all employees and contractors
Responsible Disclosure
We value the security research community. If you discover a vulnerability in our platform, please report it responsibly to security@dealgrounds.com. We commit to acknowledging reports within 48 hours and will work with you to understand and remediate the issue.
Questions?
For security inquiries, audit requests, or to request our SOC 2 report, please contact our security team at security@dealgrounds.com.