SECURITY & TRUST

Security designed for financial services.

SellWizr combines independent assurance with security practices built to protect your revenue workflows.

SOC 2 · TYPE II

Independent assurance

SellWizr has completed a SOC 2 Type II examination.

AICPA SOC 2 Type II Service Organization mark
INDEPENDENT ASSURANCE

SOC 2 Type II

SOC 2 gives risk teams independent insight into a service organization’s controls. SellWizr has completed a Type II examination, evaluated over a period of time rather than a single point in time.

Independent review

An independent CPA firm examined SellWizr’s controls — not just our own assessment.

Type II

Type II checks both how controls were designed and whether they worked throughout the examination period.

Useful during vendor review

The report gives your security and risk teams detail to use in their own assessment.

ReportSOC 2 Type II
Availability
DATA PROTECTION

Protecting information throughout its lifecycle.

Protecting information takes more than one control — how it’s transmitted, stored, accessed, and handled internally.

Encryption in transit

Data moving between your systems and SellWizr can’t be read in transit.

Technical detail: TLS 1.2 or higher.

Encryption at rest

Stored data stays protected even if the underlying storage were accessed directly.

Technical detail: AES-256.

Key & secret management

Encryption keys can stay under your control where required. Credentials and tokens are kept out of application logs.

Technical detail: customer-managed keys where required; IPs and emails are hashed before use as lookup keys.

Retention & deletion

Retention and deletion timelines depend on your deployment and are confirmed during onboarding and security review.

INFRASTRUCTURE SECURITY

Security extends below the application layer.

Application security depends on the infrastructure beneath it — cloud environment, change process, and monitoring.

Cloud environment

SellWizr runs on Amazon Web Services (AWS), using containerized compute behind a load-balanced, HTTPS-only entry point.

Deployment & change management

Changes deploy through an automated pipeline with health checks — a failing release rolls back automatically.

Scaling & availability

The application runs across multiple containers and scales automatically with traffic.

Deployment options

Managed or customer-hosted deployment options are matched to your architecture during technical discovery.

IDENTITY & ACCESS

People and systems only get access to what they need.

Access is limited to what people and systems actually need.

Role-based access

Access to customer and account data follows role-based controls tied to responsibilities.

Network isolation

Network-level isolation keeps environments and traffic paths separated.

APPLICATION SECURITY

Security is part of how we build.

Security is built into the application, not bolted on afterward.

Protecting public-facing tools

Public forms use rate limits, CAPTCHA, and automatic blocking of repeat abuse. CAPTCHA can’t be disabled in production.

Duplicate-action protection

Repeated submissions are recognized and treated as one action, so a retry or double-click can’t create duplicates.

SECURITY OPERATIONS

Preparing to detect, respond, and recover.

Prevention is only part of security — we also build in the visibility to identify and investigate issues.

Structured, secret-free logging

Security events are logged in structured entries designed so tokens, credentials, and full emails or IP addresses are never stored in the clear.

Request tracing

Each request carries an ID threaded through the security layer for end-to-end tracing.

Incident-response and escalation specifics are shared during a security review.

AI SECURITY & GOVERNANCE

Responsible AI starts with responsible data handling.

Financial institutions evaluate AI differently from ordinary software — what it can do, what it can access, and who stays in control.

Explainable by design

Every recommendation shows the signals behind it — no hidden or unexplainable scores.

Your CRM stays in control

SellWizr doesn’t replace your CRM — it surfaces signals and pushes recommendations back into it, so a person decides what happens next.

More on model providers, data handling, and governance is available during a security review — .

PRIVACY & GOVERNANCE

Clear rules for how information is handled.

Our Privacy Policy governs how personal data is collected, used, and protected. Retention, deletion, subprocessor, and DPA questions are answered during a privacy or security review.

Read the Privacy Policy
THIRD-PARTY RISK

Our security boundary includes the services we depend on.

Cloud and AI providers become part of your risk surface. SellWizr shares vendor and provider specifics during a security review.

RESILIENCE

Planning for more than the happy path.

Reliable systems require preparation for disruption, not just day-to-day operation.

Deployment resilience

The application runs across multiple containers with automated health checks and automatic rollback. Backup and continuity specifics are confirmed during a security or architecture review.

DOCUMENTATION

Security documentation

Additional materials are available as part of SellWizr’s security and vendor-review process.

SOC 2 Type II Report

Independent examination documentation for qualified customers and prospects.

Available on request

Privacy Policy

PublicView →

Terms of Service

PublicView →
FREQUENTLY ASKED

Enterprise security FAQ

Answers to the questions security, risk, architecture, privacy, and procurement teams most often ask when evaluating SellWizr.

Need something more specific?

Our team can work directly with security, risk, architecture, privacy, or procurement during evaluation.