Enterprise grade security

Security without compromise.

In M&A, IPOs and financial structuring, nothing matters more than protecting documents and preserving the anonymity of the parties involved. Every control below exists to answer the question that counts: who accessed what, when, and with which permission.

256-bit
Individual encryption per project
99.95%
Uptime guaranteed by contract
100%
Of events logged in the audit trail

Certifications and compliance

ISO 27001

Certified information security management system.

SOC 1, 2 & 3

Audited controls for security, availability and confidentiality.

SSAE18 / ISAE 3402

Internationally recognized control reports.

LGPD & GDPR

Data handling aligned with Brazilian and European law, with a DPA available.

Regular pen tests

Periodic third-party intrusion testing, with reports available.

Microsoft Azure

World-class cloud infrastructure with redundancy and continuous backup.

Encryption

256-bit, individual per project

We are the only company with individual encryption per project: every deal gets its own keys, guaranteeing total isolation. An incident in any other environment never reaches yours. In transit, end-to-end TLS 1.2.

Zero knowledge

Not even we can access your files

The architecture prevents the Deallink team from reading document content. Our project team manages structure, permissions and support — never the confidential content of the transaction.

Access

MFA, token, SSO and IP restriction

Mandatory two-factor authentication, token login, integration with corporate identity providers and IP allowlisting. Sessions can be terminated and permissions revoked in real time.

Document protection

Dynamic watermark and locks

Every view carries the user, date and IP. Granular locks on viewing, printing and downloading, security by file type, and a customized, traceable disclaimer on every opening.

Redaction

Hide and disclose under control

Hide confidential information with a click, automatically by default (tax IDs, emails, dates, figures) and by category (GDPR/LGPD, Compliance, Clean Team). Redacted terms lose search power.

Audit

Immutable full audit trail

Every login, view, download and permission change is logged with date, time, user and IP — exportable at any time and valid as documentary evidence of the process.

Continuity

99.95% contractual uptime

100% cloud-based SaaS, with server redundancy in a certified environment, continuous backup and a tested recovery plan. Uptime guaranteed by contract.

Governance

Multiple administration levels

Administrator profiles with distinct scopes, segregation of duties and a dedicated trail of administrative actions — preventing a single credential from concentrating all power over the deal.

Confidentiality applied to the document, not just access.

Integrated redaction lets you release a document without exposing what can't yet be disclosed — by automatic default, compliance category, or manual selection — and revert it with one click when the deal phase allows.

Redacted words are no longer indexed by full-text search, eliminating indirect leaks through search.

Document with confidential areas hidden by Deallink redaction
Deallink access report with user, document, date, time and action

Traceability that stands up to an audit.

Access reports, unaccessed-document reports, per-user and system reports — with filters by date, folder, group and action, exportable at any point in the process. It's the evidence that information moved exactly as it should have.

Security across the entire deal lifecycle.

1. Opening

Dedicated environment, project-exclusive keys, structure and groups defined with your team.

2. Running

Granular permissions, redaction, watermark, approved Q&A and continuous access monitoring.

3. Closing

Full export with index, Q&A and audit trail — the complete file of the transaction.

4. Archiving

24/7 digital Compliance Archive or encrypted read-only USB drive, with audited chain of custody.

Frequently asked questions from IT and compliance teams

Where is the data hosted?

On Microsoft Azure infrastructure, with redundancy and continuous backup. The hosting region can be set according to the data sovereignty requirement of your deal.

Can Deallink read my documents?

No. The zero-knowledge architecture, combined with individual encryption per project, prevents our team from accessing file content.

Do you respond to our IT team's vendor assessment?

Yes. We send technical documentation, the latest pen test report, certifications, and answer your team's security questionnaire.

Can access be revoked during the process?

Yes, at any time. Permission changes and revocations take effect immediately, including for sessions already open.

What happens to the documents at the end of the transaction?

You receive the complete deal file and can choose the digital Compliance Archive (24/7 web access, up to 3 users) or a physical one (encrypted, read-only USB drive with legal validity).

Need our security questionnaire?

We send technical documentation, certifications and the pen test report, and respond to your IT team's vendor assessment.

Request documentation