Trust · SecurityUpdated 12 August 2026
Security at CREdili

Security, by design.

Every closing runs on documents that must be protected — contracts, financials, identity, and money. Here is how we safeguard yours.

SOC 2 Type II · In progress TLS 1.3 AES-256 at rest SSO / MFA

How we protect your deal

Encryption everywhere

TLS 1.3 in transit and AES-256 at rest. Document uploads are encrypted end-to-end between your browser and our storage.

Least-privilege access

Only members of your deal room can read its files. Internal access requires SSO, MFA, and is logged and time-bounded.

Continuous monitoring

Runtime detection, dependency scanning, and 24/7 alerting on our production environment, with paged on-call response.

U.S. data residency

Customer data is hosted in isolated, SOC 2-audited AWS regions in the United States, with redundancy across availability zones.

Backups & recovery

Encrypted, versioned backups with defined RPO/RTO. Restores are tested quarterly.

Responsible AI

CREdili Counsel AI runs on isolated tenancy and does not use your deal content to train foundation models for other customers.

Our practices

Reporting a vulnerability

We welcome coordinated disclosure. If you believe you've found a security issue, please email contact with a description, reproduction steps, and any relevant proof. Please do not test against production data or other customers. We will acknowledge receipt within two business days.

Need our security package?

We share our SOC 2 report, penetration test summary, and DPA under NDA.

Contact security