Security

Last updated: August 12, 2026

Security at Provenance

Provenance handles the most sensitive information in finance — live deal models, diligence data rooms, and the material non-public information (MNPI) behind every investment decision. Protecting it isn't a feature; it's the product.

Our Trust Center has live compliance status, our controls, and audit reports, and lets you request our SOC 2 Type I report under NDA.

At a glance

SOC 2 Type I
Independently audited; Type II underway.
AES-256 at rest
Databases, storage, and backups encrypted.
TLS 1.2+ in transit
HSTS enforced on every connection.
Per-deal isolation
App gates plus database row-level security.
No retention, no training
By contract with our AI providers.
Immutable audit trail
Append-only record of every change.

Compliance & monitoring

  • SOC 2 Type I across Security, Availability, and Confidentiality; the Type II audit is in progress.
  • Controls monitored continuously, not just at audit time.
  • Reports and DPAs in our Trust Center.

Encryption

  • TLS 1.2+ in transit, with HSTS on every connection.
  • AES-256 at rest across databases, storage, and backups.
  • Keys in hardware-backed key management, rotated regularly.

Infrastructure & hosting

  • Hardened, SOC 2-compliant cloud, hosted in the US.
  • Managed PostgreSQL with backups and network isolation.
  • Global edge with automatic TLS and DDoS protection.

Tenant & deal isolation

  • You only see deals you're granted — colleagues included.
  • App-level gates check deal and role on every request.
  • Row-level security binds every query to your organization.

Identity & access

  • Single sign-on through Microsoft and Google.
  • Your own MFA and offboarding policies apply automatically.
  • Staff don't access customer data by default.

AI & your data

  • Deal content goes to Google Vertex AI under enterprise terms: not retained, never trained on.
  • AI only sees what the signed-in user is already allowed to see.
  • Optional voice dictation uses a separate speech-to-text provider; we never store the audio. See our Privacy Policy.

Audit logging & integrity

  • Every change recorded in an append-only trail.
  • See exactly what moved between versions.
  • Evidence packages for your own compliance needs.

Application & network

  • Hardened HTTP headers, including HSTS.
  • Rate limiting and abuse protection on auth and API.
  • Input validation against injection and XSS.

Secure development

  • Mandatory review on security-sensitive changes.
  • Automated tests, linting, and type checks before every ship.
  • Secret and dependency scanning, patched quickly.

Vulnerability management

  • Continuous automated scanning.
  • Periodic third-party penetration testing.
  • Findings triaged by severity and tracked to fix.

Retention & deletion

  • Data kept only while your account is active.
  • Purged from active systems within 30 days, backups within 90.
  • Deleted or returned on termination. See our Privacy Policy.

Availability & continuity

  • Automated backups with point-in-time recovery.
  • Redundant infrastructure built to tolerate failures.
  • Monitoring and synthetic checks catch issues fast.

Personnel & vendors

  • Security training and confidentiality for all staff.
  • Least-privilege access, revoked promptly on departure.
  • Vendors reviewed for security before any access.

Incident response

  • Documented detect, contain, and recover process.
  • We notify you without undue delay if your data is affected.
  • You get the information you need to meet your obligations.

Responsible disclosure

Found a security issue? Email support@provenancexl.com with steps to reproduce, and please hold off on public disclosure until we've had a chance to fix it. We aim to acknowledge within two business days and won't pursue legal action against good-faith researchers.

Contact