Security
Last updated: August 12, 2026
Security at Provenance
Provenance handles the most sensitive information in finance — live deal models, diligence data rooms, and the material non-public information (MNPI) behind every investment decision. Protecting it isn't a feature; it's the product.
Our Trust Center has live compliance status, our controls, and audit reports, and lets you request our SOC 2 Type I report under NDA.
At a glance
- SOC 2 Type I
- Independently audited; Type II underway.
- AES-256 at rest
- Databases, storage, and backups encrypted.
- TLS 1.2+ in transit
- HSTS enforced on every connection.
- Per-deal isolation
- App gates plus database row-level security.
- No retention, no training
- By contract with our AI providers.
- Immutable audit trail
- Append-only record of every change.
Compliance & monitoring
- SOC 2 Type I across Security, Availability, and Confidentiality; the Type II audit is in progress.
- Controls monitored continuously, not just at audit time.
- Reports and DPAs in our Trust Center.
Encryption
- TLS 1.2+ in transit, with HSTS on every connection.
- AES-256 at rest across databases, storage, and backups.
- Keys in hardware-backed key management, rotated regularly.
Infrastructure & hosting
- Hardened, SOC 2-compliant cloud, hosted in the US.
- Managed PostgreSQL with backups and network isolation.
- Global edge with automatic TLS and DDoS protection.
Tenant & deal isolation
- You only see deals you're granted — colleagues included.
- App-level gates check deal and role on every request.
- Row-level security binds every query to your organization.
Identity & access
- Single sign-on through Microsoft and Google.
- Your own MFA and offboarding policies apply automatically.
- Staff don't access customer data by default.
AI & your data
- Deal content goes to Google Vertex AI under enterprise terms: not retained, never trained on.
- AI only sees what the signed-in user is already allowed to see.
- Optional voice dictation uses a separate speech-to-text provider; we never store the audio. See our Privacy Policy.
Audit logging & integrity
- Every change recorded in an append-only trail.
- See exactly what moved between versions.
- Evidence packages for your own compliance needs.
Application & network
- Hardened HTTP headers, including HSTS.
- Rate limiting and abuse protection on auth and API.
- Input validation against injection and XSS.
Secure development
- Mandatory review on security-sensitive changes.
- Automated tests, linting, and type checks before every ship.
- Secret and dependency scanning, patched quickly.
Vulnerability management
- Continuous automated scanning.
- Periodic third-party penetration testing.
- Findings triaged by severity and tracked to fix.
Retention & deletion
- Data kept only while your account is active.
- Purged from active systems within 30 days, backups within 90.
- Deleted or returned on termination. See our Privacy Policy.
Availability & continuity
- Automated backups with point-in-time recovery.
- Redundant infrastructure built to tolerate failures.
- Monitoring and synthetic checks catch issues fast.
Personnel & vendors
- Security training and confidentiality for all staff.
- Least-privilege access, revoked promptly on departure.
- Vendors reviewed for security before any access.
Incident response
- Documented detect, contain, and recover process.
- We notify you without undue delay if your data is affected.
- You get the information you need to meet your obligations.
Responsible disclosure
Found a security issue? Email support@provenancexl.com with steps to reproduce, and please hold off on public disclosure until we've had a chance to fix it. We aim to acknowledge within two business days and won't pursue legal action against good-faith researchers.
Contact
- Compliance status & reports: Vanta Trust Center
- Security, compliance & DPA: support@provenancexl.com
- General support: support@provenancexl.com
- Privacy Policy · Terms of Service