The controls your security team signs off on.
Prodeal protects deal and due diligence documents with the controls institutional lenders demand of any system of record.
Prodeal is SOC 2 compliant, audited annually against the AICPA SOC standard. Trusted by leading banks and publicly traded lenders to hold the documents at the center of their deals.

Encryption and infrastructure.
Bank-grade encryption at every layer. Isolated per-customer storage, unique keys, and real-time backups that keep pace with the deal.
In transit
TLS 1.2 on every request between your team and Prodeal.
At rest
AES-256 on every document stored on disk.
Isolated storage
Every customer’s files sit in a separate storage bucket, encrypted with its own unique key.
Real-time backups
Continuous recovery points that keep pace with the deal.
Access, in three layers.
Institutional access control is not one setting. It is layered — at the platform, at the file, and at the user — so the wrong person cannot see the wrong thing at any layer.
Platform Layer
- Single sign-on.
- A real-time, time-stamped audit trail of every action.
- Granular roles and permissions down to the folder and the file.
File Layer
- Restrict download, print, and screenshot on any document.
- Custom watermarks (name, email, organization, timestamp).
- Export the activity log to CSV for your SIEM.
User Layer
- Multi-factor authentication for users and guests.
- Guest invite and inactive-guest expiration.
- Guest access approval.
- Role restrictions per user.
The audit trail.
Every file, status, and access change is recorded with a time stamp, and the record cannot be altered. The report an examiner asks for is the same record your team works in every day, which is why audit prep stops being a fire drill.
Want to walk your security team through it?
The fastest way to prove Prodeal meets your policy is to walk your team through the platform. Live review in thirty minutes. A Supplier Data Processing Agreement is available on request, alongside the SOC 2 report.


