DealAtlas Legal

Security Policy

Effective Date: July 1, 2025 | Last Updated: July 1, 2025

DealAtlas takes the security of our platform and your data seriously. This Security Policy describes the measures we take to protect information and what you can do to help keep your account secure.

1. PLATFORM SECURITY MEASURES

1.1 Data Encryption

All data transmitted between your browser and the DealAtlas platform is encrypted using TLS (Transport Layer Security). Sensitive data stored in our systems is encrypted at rest using industry-standard encryption protocols.

1.2 Access Controls

Access to DealAtlas systems and customer data is restricted to authorized personnel on a need-to-know basis. We enforce role-based access controls and require multi-factor authentication for all internal system access.

1.3 Infrastructure Security

DealAtlas is hosted on cloud infrastructure with SOC 2 Type II certification. We conduct regular vulnerability assessments and maintain intrusion detection systems. Our infrastructure providers maintain physical security controls at all data center locations.

1.4 Monitoring & Logging

We continuously monitor platform activity for anomalous behavior, unauthorized access attempts, and potential security incidents. Security logs are retained for a minimum of 12 months for forensic and compliance purposes.

1.5 Security Reviews

We conduct periodic security reviews and work with third-party security professionals to assess platform vulnerabilities. Critical vulnerabilities are remediated on a priority basis with timelines proportionate to risk severity.

2. ACCOUNT SECURITY — YOUR RESPONSIBILITIES

You are responsible for maintaining the security of your DealAtlas account. We strongly recommend using a strong, unique password, enabling multi-factor authentication if available, not sharing login credentials, logging out on shared computers, and reviewing account activity regularly.

DealAtlas will never ask for your password via email, phone, or chat. If you receive such a request, treat it as a phishing attempt and report it to security@dealatlas.com immediately.

3. VULNERABILITY DISCLOSURE

If you discover a potential security vulnerability in the DealAtlas platform, we ask that you report it to us responsibly before public disclosure. Please contact security@dealatlas.com with a description of the vulnerability and impact, steps to reproduce, and any relevant screenshots, logs, or proof-of-concept code.

We will acknowledge your report within 2 business days and provide a remediation timeline based on severity. We ask that you give us reasonable time to address the issue before public disclosure and that you do not access, modify, or delete data belonging to other users in the course of your research.

DealAtlas does not currently offer a formal bug bounty program, but we will publicly acknowledge responsible disclosures upon request.

4. INCIDENT RESPONSE

In the event of a security incident that affects your data, DealAtlas will investigate and contain the incident as quickly as possible, notify affected users within 72 hours of confirming a breach that impacts personal data where required by law, provide details of affected data and remediation steps, and cooperate with law enforcement and regulatory authorities as required.

5. THIRD-PARTY SECURITY

DealAtlas works with third-party vendors who may process or store data on our behalf. We evaluate vendors for security practices before engagement and require contractual commitments to maintain appropriate security standards. We do not share data with vendors beyond what is necessary to provide the Services.

6. CONTACT

For security-related questions, vulnerability reports, or incident notifications, contact:

DealAtlas Security Team | security@dealatlas.com | dealatlas.com

© 2025 DealAtlas. All rights reserved.