Security and compliance
Designed with credit-grade security controls and a transparent posture.
SOC 2-aligned controls — certification plannedOur security posture
CreditApp Genie is designed with SOC 2-aligned controls across availability, confidentiality, and processing integrity. We have not yet completed a formal SOC 2 certification — we plan to pursue it as the product matures. We are transparent about this because we believe credit teams deserve honest security communication.
Tenant isolation
Every organisation is logically isolated at the data layer. No cross-tenant data access is possible by design.
Encryption in transit
All traffic is encrypted with TLS 1.2+ . There are no unencrypted endpoints.
Encryption at rest
Database storage is encrypted at rest. Backup snapshots are also encrypted.
Field-level encryption
Sensitive fields — tax IDs, bank account details, and SSNs — are encrypted at the field level, separate from general storage encryption.
Multi-factor authentication
MFA is required for all internal users (credit team members, admins). TOTP-based authenticator apps are supported.
Role-based access control
Granular roles — Admin, Reviewer, Analyst, Requestor — control which data each user can view or modify.
Immutable audit trail
Every action (view, edit, decision) is recorded with a timestamp and user ID. The audit log cannot be modified or deleted.
Consent-version capture
The version of the privacy notice shown to applicants is recorded alongside their consent at the time of submission.
Data retention controls
Administrators can configure retention periods per data category. Automated deletion runs on schedule.
Magic-link security
Application links are single-use, time-limited tokens. Expired or used links cannot be replayed.
Request security documentation
We provide a security questionnaire, architecture overview, and sub-processor list to qualified prospects under NDA.
Request documentation