UpSlide Security & Compliance

Security Built for Financial Services

From first vendor assessment to full deployment, leading financial services firms trust UpSlide with their most sensitive workflows.

Independently Verified

SOC 2 Type II certified and ISO 27001 accredited. The certifications your compliance and procurement teams require – backed by independent audits.

Deal Data Stays Yours

UpSlide never stores your documents, models, or deal content. We operate as a read-only add-in – sensitive data is not kept on our servers.

Minimal IT Overhead

Fully supported deployment by an in-house team of experts, with automatic updates in the background. No ongoing maintenance required from your team.

The Standards Your Compliance Team Expects

AICPA SOC 2 compliance badge. Security verification. ISO 42001 logo. Security standard for AI management systems. RGPD logo with stars around the edge

SOC 2 Type II Certified

Our SOC 2 Type II certification confirms that UpSlide’s security controls, covering availability, confidentiality, and data integrity, are independently audited and operating effectively over time. We share the full report with clients on request, supporting your vendor due diligence process from day one.

ISO 27001

ISO 27001 is the internationally recognized standard for Information Security Management. UpSlide is fully certified, giving your compliance team a globally accepted benchmark for how we manage and protect information assets.

AI Features Built for Regulated Environments

Your Own Dedicated Foundry

AI requests are processed within a dedicated Azure AI Foundry, accessible only to your firm. No other client can access your foundry.

Encrypted In Transit

All data is sent through encrypted channels between the add-in and your dedicated foundry. Your firm’s data is never exposed in transit.

No Data Stored or Reused

No data is stored, reused, or used for training. Everything processed through your foundry stays private to your firm.

Validated Models Only

Every AI model is tested against our benchmark suite before production use. Each UpSlide AI feature has its own independent benchmark to pass.

Helping Deal and Client Teams Deliver at Speed

Azure-Hosted, Encrypted End-to-End

All communications are encrypted in transit using TLS 1.2 and AES-256 – the same standards expected across financial services. No document or deal content is ever transmitted to UpSlide servers.

Rigorous Code Standards

Every release of UpSlide is scanned before deployment, covering both the add-in and server-side code. We test against all supported Microsoft 365 versions, including Office 365 Insider builds. Vulnerabilities are classified and prioritized using the SANS Institute methodology.

SSO via Microsoft Entra ID

UpSlide integrates with Microsoft Entra ID so user access is governed by your existing identity infrastructure, not a separate system to manage. We use delegated permissions only, meaning UpSlide acts on behalf of the signed-in user and cannot access content independently.

Zero-Touch Update Deployment

UpSlide releases updates every two weeks, downloaded and installed silently in the background, no action required from IT teams or end users. Your firm always runs the latest, most secure version, with Microsoft 365 compatibility maintained automatically.

Need the Full Technical Details?

Our support site has in-depth documentation on communication protocols, endpoint security, software architecture, and more.

Trust UpSlide with Your Most Sensitive Work

Learn why leading financial services firms trust UpSlide’s stringent security practices with their most important work.

FAQs

Is UpSlide SOC 2 Certified?

Yes. UpSlide is SOC 2 Type II certified, meaning our security controls are independently audited on an ongoing basis, not just at a point in time. You can request the full report under NDA.

Is UpSlide ISO 27001 Certified?

Yes. ISO 27001 is the internationally recognized standard for Information Security Management, and UpSlide is fully certified. Full documentation is available on request.

Can UpSlide Support Our Internal Vendor Assessment Process?

Yes. We’re experienced working with IT and InfoSec teams at financial services firms and can provide security documentation, answer technical questionnaires, and arrange a dedicated security review call.

Does UpSlide Store Any of Our Documents or Deal Content?

No. UpSlide operates as a read-only add-in. Your documents, models, and deal content are never transmitted to or stored on UpSlide servers.

Where Is UpSlide's Infrastructure Hosted?

UpSlide is hosted entirely on Microsoft Azure, in the West Europe and France Central regions.

How Is Data Encrypted?

All communications between UpSlide and our servers are encrypted using TLS 1.2 and AES-256, both in transit and at rest.

Is Our Data Used to Train AI Models?

No. No data processed through UpSlide’s AI features is stored, reused, or used for training.

Is Our AI Data Kept Separate From Other Clients?

Yes. AI requests are processed within a dedicated Azure AI Foundry accessible only to your firm. No other client can access your foundry.

How Do You Decide Which AI Models to Use?

Every model is tested against a benchmark suite before use in production. Each UpSlide AI feature has its own independent benchmark, and a model must pass it individually to be approved for that feature.

How Is UpSlide Deployed?

UpSlide is deployed as a Microsoft 365 add-in, distributed silently via standard software management tools. No end-user action is required.

How Are Updates Managed?

Updates are released every two weeks and installed automatically in the background. No IT intervention or redeployment is needed.

Does UpSlide Support Single Sign-On?

Yes. UpSlide integrates with Microsoft Entra ID (formerly Azure AD), allowing users to authenticate through your existing SSO infrastructure.

Can We Use Our Own Entra ID Application?

Yes. Firms that require it can supply their own Entra ID application rather than using UpSlide’s multi-tenant application.

The missing layer in your AI document workflow