Security and activation
Confidential use has an explicit activation process.
A workspace starts with synthetic data. Payment does not activate processing of confidential borrower information.
Before confidential processing
The institution and operator must record intended use, data rights, processing locations, retention, provider eligibility, security review and a named credit owner. Assisted use requires a separate authorization.
Access and evidence
The application uses organization membership, role checks, verified email and two-factor authentication. Source files are kept in private encrypted storage. Downloads require current membership and are recorded in the audit trail. Source versions are hashed and included in a frozen manifest.
Provider controls
Each approved route identifies its exact model, endpoint, permitted data class, retention terms, region terms and expiry. A missing required provider must produce an incomplete review. It cannot trigger a silent switch to another provider.
Deployment evidence
Security claims require current operational evidence. Independent penetration testing, customer approvals and lending efficacy have not been established. Ask for the current deployment, restoration and control-validation record during diligence.
Report a concern
Use the contact form to report a security concern. Include enough detail to identify the affected flow, but do not submit credentials or borrower documents.