A&A DealFlow

Security

A security-focused architecture for company access and data boundaries.

A&A DealFlow uses company-level tenant isolation, server-side permission checks, protected storage paths, audit logging, verified account flows, and privacy-conscious AI boundaries. Each control below carries its current status.

Status legend

Implemented
Present in the current product build and covered by project verification suites.
In Progress
Present in development or operational work but not fully release-ready.
Planned
Not currently available or complete.

Security controls

Implemented controls are present in the product and covered by the project’s verification suites. Deployment-dependent controls remain In Progress, and unavailable work stays Planned.

Implemented

Account security

Managed authentication supports verified accounts, password reset, protected session flows, and rate-limited account actions.

Implemented

Tenant isolation

Tenant tables use company identifiers, application-layer scoping, and database row-level security as defense in depth. Cross-tenant tests cover protected surfaces.

Implemented

Role-based permissions

Each request resolves company membership and permission keys server-side. Interface visibility is not the authorization boundary.

Implemented

Audit logging

Sensitive administrative and product events are recorded in append-only audit structures according to the implemented event set.

In Progress

File protection

Files use company-scoped storage paths and protected download flows. Exact encryption and retention statements require deployment verification.

Implemented

Employee invitations

Invitation flows use verified identity checks, expiration, one-time use, and protected preview information. Removing a member revokes affected company sessions.

Implemented

AI privacy

The AI Help Assistant is read-only, permission-aware, and separated from write modules. Customer records are excluded from AI context by default for the MVP.

Planned

Integration security

Future provider connections are designed to keep tokens server-side and verify provider events. RingCentral remains Planned.

In Progress

Backups and recovery

Production backup, point-in-time recovery, restore testing, retention, and recovery commitments are deployment-dependent and currently In Progress.

In Progress

Monitoring and incident response

Monitoring, escalation, customer notification, and response procedures must be documented and operational before a release-ready label is used.

Implemented

Responsible disclosure

Send security reports to support@aadealflow.com. Do not include active credentials or customer data in an initial report.

Last reviewed: July 18, 2026 by A&A Development LLC.

Security questions

Is A&A DealFlow SOC 2 certified?
No certification is claimed. If that changes, the page will name the exact scope and verification date.
How is one company kept separate from another?
The architecture combines company-scoped records, application-layer checks, database row-level security, protected storage paths, and cross-tenant tests. Exact production status appears beside each control.
Can the AI assistant change data?
No. It is architecturally read-only and has no write tools.
Where can I send a security question?
Use support@aadealflow.com or Contact Sales for procurement routing. Do not send passwords, tokens, or customer data.

Review security requirements against verified controls.