Trust & safety
Security
Your money and your pipeline are on the line, so security is built into DealOS from the ground up — not bolted on.
Last updated: February 2026
Account protection
- Passwords are never stored in plain text — they are securely hashed using industry-standard algorithms.
- Optional two-factor authentication (TOTP) adds a second layer of protection to your account.
- Trusted-device management lets you review and revoke active sessions.
- Sessions are managed with secure, HTTP-only cookies.
Data isolation
Your workspace is private. Every query that reads deals, buyers, tasks, or documents is scoped to your account, so one user can never access another user's data. Administrative tools are gated behind separate, role-checked access.
Encryption
Data is encrypted in transit using TLS. Sensitive files and documents are stored in private, access-controlled storage and are served only through authenticated, permission-checked routes — never from a public URL.
Infrastructure
DealOS runs on trusted, industry-leading cloud infrastructure with managed Postgres and edge-delivered hosting. This gives us automated backups, network isolation, and a hardened baseline maintained by our providers.
Your role in security
- Enable two-factor authentication from your account settings.
- Use a strong, unique password you don't reuse elsewhere.
- Review your trusted devices periodically and revoke any you don't recognize.
- Never share your credentials — DealOS staff will never ask for your password.
Responsible disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, please email security@dealos.app with details so we can investigate and respond quickly. Please give us a reasonable opportunity to address the issue before public disclosure.
For questions about how we handle data, see our Privacy Policy.