DMW FinTel was built by a CFA and fractional CFO who handles sensitive financial data every day. Security isn't an afterthought -- it's foundational. This page documents exactly how we protect your data, who can access it, and how our AI handles it. No vague promises.
All financial data in FinTel is encrypted in transit and at rest, logically isolated per tenant, and stored exclusively in the United States.
Who can access what -- and how we verify it. Every endpoint enforces role and scope checks; there is no client-side-only authorization.
This is the #1 question prospects ask. Here is the full, unambiguous answer.
Every layer of the FinTel stack -- network, application, database, and monitoring -- is hardened by design.
npm audit)We are building to enterprise compliance standards from day one. Here is where we stand today.
We engage a short list of subprocessors: Cloudflare (CDN, WAF, DNS, encrypted backup storage), Hetzner (US hosting), Stripe (billing), MailerSend (transactional email), and AI model providers under NDA. The full list with data-touched details is available in our security documentation package, and enterprise customers are notified 30 days before any change.
Production customer data is accessible only to the founder. No other personnel have production access; a documented break-glass procedure governs any future change.
The processes behind the technology: incident response, business continuity, and change management.
FinTel's transaction data room is built to the security standards that M&A advisors, investment bankers, and acquirers expect.
If you discover a vulnerability or have a security question, contact us. We respond to all reports within 24 hours.
Our vulnerability disclosure policy: acknowledgment within 24 hours, investigation within 5 business days, and safe harbor for good-faith research. Full policy at docs/security/vdp.md (available on request). We will not pursue legal action against researchers who respect our scope and give us reasonable time to remediate.
For general security questions or to request our full security documentation package, contact Mike directly.
Answers to the questions your compliance team will ask.