Security

Last updated: July 2026

Security is foundational to a platform that sits in the middle of lending decisions and capital flows. This page summarizes how we think about protecting the Service and the data our customers entrust to it.

Data protection

  • Data is encrypted in transit, and access to production systems is limited to authorized personnel on a need-to-know basis.
  • Every tenant's data is logically isolated; the platform is built so one tenant can never resolve another tenant's records.
  • Actions across the platform are recorded to an auditable trail for traceability and review.

Infrastructure

The Service runs on reputable cloud infrastructure with network controls, least-privilege access, and monitoring. Changes ship through reviewed, version-controlled pipelines.

Explainability and auditability

Decisions surfaced by the platform are designed to be explainable and reviewable — with reason codes and an audit record — so your team and your regulators can understand how an outcome was reached.

Compliance roadmap

We are building toward formal third-party attestations (e.g. SOC 2). Your security and compliance teams should evaluate the platform as part of their standard due diligence.

Responsible disclosure

If you believe you've found a security issue, please report it through our contact form so we can investigate. We appreciate responsible disclosure and will work with you.