Security designed for financial services.
SellWizr combines independent assurance with security practices built to protect your revenue workflows.
SOC 2 Type II
SOC 2 gives risk teams independent insight into a service organization’s controls. SellWizr has completed a Type II examination, evaluated over a period of time rather than a single point in time.
Independent review
An independent CPA firm examined SellWizr’s controls — not just our own assessment.
Type II
Type II checks both how controls were designed and whether they worked throughout the examination period.
Useful during vendor review
The report gives your security and risk teams detail to use in their own assessment.
A 30-second overview for evaluators.
A quick view of the areas most often reviewed during security diligence.
Independent Assurance
Independent assurance over the controls in scope.
Learn more ↓Data Protection
Information is protected in transit, at rest, and when accessed.
Learn more ↓Identity & Access
Role-based access with network-level isolation.
Learn more ↓Cloud & Infrastructure
Runs on AWS, with controls around deployment and monitoring.
Learn more ↓Application Security
Rate limiting, abuse detection, and duplicate-action protection.
Learn more ↓Security Operations
Secret-free logging and request tracing support investigation.
Learn more ↓AI Security & Governance
AI recommendations are explainable, and your CRM stays the system of record.
Learn more ↓Privacy & Governance
Governed by our Privacy Policy and addressed during procurement.
Learn more ↓Protecting information throughout its lifecycle.
Protecting information takes more than one control — how it’s transmitted, stored, accessed, and handled internally.
Encryption in transit
Data moving between your systems and SellWizr can’t be read in transit.
Technical detail: TLS 1.2 or higher.
Encryption at rest
Stored data stays protected even if the underlying storage were accessed directly.
Technical detail: AES-256.
Key & secret management
Encryption keys can stay under your control where required. Credentials and tokens are kept out of application logs.
Technical detail: customer-managed keys where required; IPs and emails are hashed before use as lookup keys.
Retention & deletion
Retention and deletion timelines depend on your deployment and are confirmed during onboarding and security review.
Security extends below the application layer.
Application security depends on the infrastructure beneath it — cloud environment, change process, and monitoring.
Cloud environment
SellWizr runs on Amazon Web Services (AWS), using containerized compute behind a load-balanced, HTTPS-only entry point.
Deployment & change management
Changes deploy through an automated pipeline with health checks — a failing release rolls back automatically.
Scaling & availability
The application runs across multiple containers and scales automatically with traffic.
Deployment options
Managed or customer-hosted deployment options are matched to your architecture during technical discovery.
People and systems only get access to what they need.
Access is limited to what people and systems actually need.
Role-based access
Access to customer and account data follows role-based controls tied to responsibilities.
Network isolation
Network-level isolation keeps environments and traffic paths separated.
Security is part of how we build.
Security is built into the application, not bolted on afterward.
Protecting public-facing tools
Public forms use rate limits, CAPTCHA, and automatic blocking of repeat abuse. CAPTCHA can’t be disabled in production.
Duplicate-action protection
Repeated submissions are recognized and treated as one action, so a retry or double-click can’t create duplicates.
Preparing to detect, respond, and recover.
Prevention is only part of security — we also build in the visibility to identify and investigate issues.
Structured, secret-free logging
Security events are logged in structured entries designed so tokens, credentials, and full emails or IP addresses are never stored in the clear.
Request tracing
Each request carries an ID threaded through the security layer for end-to-end tracing.
Incident-response and escalation specifics are shared during a security review.
Responsible AI starts with responsible data handling.
Financial institutions evaluate AI differently from ordinary software — what it can do, what it can access, and who stays in control.
Explainable by design
Every recommendation shows the signals behind it — no hidden or unexplainable scores.
Your CRM stays in control
SellWizr doesn’t replace your CRM — it surfaces signals and pushes recommendations back into it, so a person decides what happens next.
More on model providers, data handling, and governance is available during a security review — .
Clear rules for how information is handled.
Our Privacy Policy governs how personal data is collected, used, and protected. Retention, deletion, subprocessor, and DPA questions are answered during a privacy or security review.
Read the Privacy PolicyOur security boundary includes the services we depend on.
Cloud and AI providers become part of your risk surface. SellWizr shares vendor and provider specifics during a security review.
Planning for more than the happy path.
Reliable systems require preparation for disruption, not just day-to-day operation.
Deployment resilience
The application runs across multiple containers with automated health checks and automatic rollback. Backup and continuity specifics are confirmed during a security or architecture review.
Enterprise security FAQ
Answers to the questions security, risk, architecture, privacy, and procurement teams most often ask when evaluating SellWizr.
Need something more specific?
Our team can work directly with security, risk, architecture, privacy, or procurement during evaluation.