Platform Solutions How it works Security Pricing Company Sign in Request access
Security by architecture

Trust the controls, not a promise.

Dealium verifies who can act, separates sensitive approvals, protects the evidence and does not take custody of customer funds.

EU-hosted · Human-approved
No custodyCustody is switched off on the current pilot: no deposit or release path is available.
Dual controlA recorded payment is confirmed by someone other than the person who submitted it. Release instructions are off on the current pilot.
EU-hostedDeal records and documents stay in the selected EU environment.

The trust model

Four boundaries protect every deal

Security is strongest when the product makes unsafe actions structurally difficult.

01

Money boundary

Banks and payment providers move funds under their own customer terms. Custody is switched off on the current pilot, so Dealium sends no payment instructions.

02

Identity boundary

Dealium records a compliance clearance for each organisation before sensitive actions unlock; on the current pilot, business-registry and sanctions-screening providers are not yet connected, so clearance is an operator decision on the evidence supplied.

03

Approval boundary

Roles and maker-checker controls separate the person preparing a sensitive action from the person approving it.

04

Evidence boundary

Encryption, malware scanning and document fingerprints protect the integrity of the record used to make decisions.

05

AI boundary

The copilot can read, flag and suggest. It cannot accept terms, alter the ledger or approve a release.

06

Audit boundary

Commercial versions, uploads, permissions, approvals and ledger entries stay attached to the transaction timeline.

Assurance status

Clear about what exists today

We distinguish implemented controls from independent certifications still on the roadmap.

Implemented

Product controls

  • Non-custodial payment architecture
  • Role-based permissions and dual approval
  • EU hosting, encryption and audit logging
  • Automated security checks in delivery

Roadmap

External assurance

  • Independent penetration testing before live-funds workflows
  • SOC 2 readiness and certification work
  • ISO 27001 readiness and certification work
  • Published assurance materials as milestones complete

Technical detail

Open only what you need

How are documents protected?
Documents are encrypted in transit and at rest, scanned on upload and fingerprinted so later changes can be detected. Access is limited by organization, deal and role.
How are counterparties screened?
Dealium records a compliance clearance for each organisation before sensitive actions unlock; on the current pilot, business-registry and sanctions-screening providers are not yet connected, so clearance is an operator decision on the evidence supplied.
What can the AI copilot do?
It may review deal context, highlight missing evidence and suggest next actions. It cannot mutate commercial state, approve money movement or access external networks without a governed integration.
What happens if a user account is compromised?
Role limits, organization boundaries, dual approval and an append-only record reduce the actions one compromised account can perform and preserve evidence for investigation.
Is Dealium certified today?
Dealium does not currently claim SOC 2 or ISO 27001 certification. Both are roadmap items; current controls and future assurance evidence are presented separately.

Review the model against your controls

Bring your compliance, finance or security lead. We will walk through the boundaries using one representative deal.

Request security review