Trust Center

How we protect your business data.

Borrowing capital means handing over the most sensitive details about your business. We treat that responsibility seriously — with bank-grade encryption, SOC 2-aligned controls, and a hard rule: we never blast your file to a directory of strangers.

Six commitments

What we promise

Encryption at rest

Every SSN, EIN, bank account number, and uploaded document is encrypted with AES-256, bound to a securely-held application key kept outside the web root. Application database backups are encrypted too.

TLS 1.3 in transit

All traffic between you and our servers — application form submits, portal sessions, document uploads — uses TLS 1.3 with HSTS-preloaded HTTPS.

No spam blast

Your file is only shared with the participating lenders and financing partners selected for your profile. We do not sell, syndicate, or rent your application to third-party lead-aggregator networks. Period.

Soft credit pull only

Our pre-qualification step uses a soft inquiry — it does not affect your credit score. A hard pull only happens after you accept an offer and the funding lender pulls one as part of underwriting.

SOC 2-aligned controls

Maker-checker rule on funded deals (you cannot approve a closing you yourself accepted). Field-level audit trail, 7-year compliance vault for submission packages, 25-year retention for adverse-action notices.

Disclosed compensation

When a lender funds your deal, they pay us a commission. The commission rate is disclosed in your closing package. You always see the same offer terms either lender-direct or through us — we never mark up your rate.

Under the hood

For your security team

If your CFO, controller, or IT lead asks for specifics, here's the technical fact-sheet.

Application data

  • AES-256 encryption at rest for SSN, EIN, DOB, bank account numbers (Laravel encrypted casts)
  • Encryption bound to a securely-held application key, stored outside the web root
  • Database backups encrypted; off-site retention 30 days
  • Field-level audit trail logs every read/write with actor + timestamp + IP

Document storage

  • Uploaded documents stored in encrypted private storage, outside the public web root
  • Files streamed through pre-signed URLs (15-minute TTL)
  • Compliance vault retains submission packages for 7 years
  • Adverse action notices retained 25 years per ECOA Reg B

Authentication

  • Mission Control: SSO-ready, role-based access control (admin / underwriter / closer / viewer)
  • Borrower Portal: passwordless magic-link, 30-minute single-use tokens
  • API: HMAC-SHA256 signed requests with replay protection
  • Maker-checker rule: separation of duties on funded deals

Network

  • TLS 1.3 with HSTS-preloaded HTTPS
  • Cloudflare WAF with managed bot mitigation
  • No third-party trackers on the borrower portal or admin
  • IP-allowlist available for partner API integrations

Compliance

  • ECOA Reg B adverse action notice generation + 25-year retention
  • TCPA-compliant consent capture with timestamp + IP
  • E-Sign Act compliant electronic signatures
  • GLBA Safeguards Rule alignment (information security program)

Incident response

  • On-call rotation with paging for production incidents
  • Customer notification commitment within 72 hours of confirmed breach
  • Independent security hardening pass completed (2026); periodic review ongoing
  • Disclosed root-cause post-mortems for any data-impacting event
Plain-English disclosures

No fine-print games

Are you a direct lender or a broker?
We're a matching and referral service working with participating lenders and financing partners. We are not a lender: we do not underwrite, make credit decisions, set terms, or fund transactions. A participating provider may compensate us when a transaction closes.
Will applying hurt my credit score?
No. Pre-qualification uses a soft inquiry, which does not affect your score. A hard pull only happens after you accept an offer and the funding lender pulls credit as part of their final underwriting — and you'll see exactly which lender is pulling before you sign.
What happens to my data if I don't get funded?
If you're declined or you decline matched offers, your application stays on file in encrypted storage so you can return later without re-entering everything. If you want your data deleted, email [email protected]. We will process the request subject to any applicable legal or regulatory retention requirements.
Who has access to my application internally?
Internal access is role-based: only the underwriter and closer assigned to your file can view sensitive fields. Every read and write is logged. SSN, DOB, and bank account numbers are masked by default — operators must explicitly unmask, and that action is also logged. Maker-checker separation of duties means a single rogue insider cannot complete a funded deal.

Ready when you are.

Apply through one secure workflow. Soft credit for pre-qualification. Any match, offer, decision, or funding timeline comes from the participating provider and is not guaranteed.