Account security
Managed authentication supports verified accounts, password reset, protected session flows, and rate-limited account actions.
Security
A&A DealFlow uses company-level tenant isolation, server-side permission checks, protected storage paths, audit logging, verified account flows, and privacy-conscious AI boundaries. Each control below carries its current status.
Implemented controls are present in the product and covered by the project’s verification suites. Deployment-dependent controls remain In Progress, and unavailable work stays Planned.
Managed authentication supports verified accounts, password reset, protected session flows, and rate-limited account actions.
Tenant tables use company identifiers, application-layer scoping, and database row-level security as defense in depth. Cross-tenant tests cover protected surfaces.
Each request resolves company membership and permission keys server-side. Interface visibility is not the authorization boundary.
Sensitive administrative and product events are recorded in append-only audit structures according to the implemented event set.
Files use company-scoped storage paths and protected download flows. Exact encryption and retention statements require deployment verification.
Invitation flows use verified identity checks, expiration, one-time use, and protected preview information. Removing a member revokes affected company sessions.
The AI Help Assistant is read-only, permission-aware, and separated from write modules. Customer records are excluded from AI context by default for the MVP.
Future provider connections are designed to keep tokens server-side and verify provider events. RingCentral remains Planned.
Production backup, point-in-time recovery, restore testing, retention, and recovery commitments are deployment-dependent and currently In Progress.
Monitoring, escalation, customer notification, and response procedures must be documented and operational before a release-ready label is used.
Send security reports to support@aadealflow.com. Do not include active credentials or customer data in an initial report.
Last reviewed: July 18, 2026 by A&A Development LLC.