Skip to content

Enterprise security at every layer.

Your borrower data, portfolio strategy, and trade secrets — protected by the same standards trusted by the world's largest financial institutions.

User AuthMFA + SSO
API GatewayRate Limited + Validated
Application LayerTenant Isolated
DatabaseRLS + AES-256
Audit LogImmutable, 7-Year
SECURITY FEATURES

Defense in depth. Every layer protected.

SOC 2-Certified Data Infrastructure

Customer data and authentication run on Supabase (SOC 2 Type II certified, AWS-hosted). Your data lives on infrastructure trusted by Fortune 500 companies.

Field-Level Encryption

Sensitive identifiers encrypted with AES-256-GCM at rest. SSNs, emails, phone numbers — encrypted individually, not just at the disk level.

Row-Level Security

Every database table enforces tenant isolation at the query level. No application bug can leak data across organizations. Zero-trust architecture by default.

Multi-Factor Authentication

TOTP-based MFA with SSO support via Google and Microsoft. Role-based access control with deal-level permissions. Every login verified.

Immutable Audit Trail

Append-only audit logging captures every user action, API call, and data change. 7-year retention. Tamper-proof by design. Regulator-ready.

PII Redaction & Retention

Sensitive data never appears in application logs. Document binaries auto-deleted after processing. Configurable retention policies with legal hold enforcement.

Compliance Status

SOC 2-Certified Data InfrastructureActive
AES-256 EncryptionActive
CCPA-ReadyActive

Security questions? Let's talk.

Request a Briefing