How we protect your business data.
Borrowing capital means handing over the most sensitive details about your business. We treat that responsibility seriously — with bank-grade encryption, SOC 2-aligned controls, and a hard rule: we never blast your file to a directory of strangers.
What we promise
Encryption at rest
Every SSN, EIN, bank account number, and uploaded document is encrypted with AES-256, bound to a securely-held application key kept outside the web root. Application database backups are encrypted too.
TLS 1.3 in transit
All traffic between you and our servers — application form submits, portal sessions, document uploads — uses TLS 1.3 with HSTS-preloaded HTTPS.
No spam blast
Your file is only shared with the participating lenders and financing partners selected for your profile. We do not sell, syndicate, or rent your application to third-party lead-aggregator networks. Period.
Soft credit pull only
Our pre-qualification step uses a soft inquiry — it does not affect your credit score. A hard pull only happens after you accept an offer and the funding lender pulls one as part of underwriting.
SOC 2-aligned controls
Maker-checker rule on funded deals (you cannot approve a closing you yourself accepted). Field-level audit trail, 7-year compliance vault for submission packages, 25-year retention for adverse-action notices.
Disclosed compensation
When a lender funds your deal, they pay us a commission. The commission rate is disclosed in your closing package. You always see the same offer terms either lender-direct or through us — we never mark up your rate.
For your security team
If your CFO, controller, or IT lead asks for specifics, here's the technical fact-sheet.
Application data
- AES-256 encryption at rest for SSN, EIN, DOB, bank account numbers (Laravel encrypted casts)
- Encryption bound to a securely-held application key, stored outside the web root
- Database backups encrypted; off-site retention 30 days
- Field-level audit trail logs every read/write with actor + timestamp + IP
Document storage
- Uploaded documents stored in encrypted private storage, outside the public web root
- Files streamed through pre-signed URLs (15-minute TTL)
- Compliance vault retains submission packages for 7 years
- Adverse action notices retained 25 years per ECOA Reg B
Authentication
- Mission Control: SSO-ready, role-based access control (admin / underwriter / closer / viewer)
- Borrower Portal: passwordless magic-link, 30-minute single-use tokens
- API: HMAC-SHA256 signed requests with replay protection
- Maker-checker rule: separation of duties on funded deals
Network
- TLS 1.3 with HSTS-preloaded HTTPS
- Cloudflare WAF with managed bot mitigation
- No third-party trackers on the borrower portal or admin
- IP-allowlist available for partner API integrations
Compliance
- ECOA Reg B adverse action notice generation + 25-year retention
- TCPA-compliant consent capture with timestamp + IP
- E-Sign Act compliant electronic signatures
- GLBA Safeguards Rule alignment (information security program)
Incident response
- On-call rotation with paging for production incidents
- Customer notification commitment within 72 hours of confirmed breach
- Independent security hardening pass completed (2026); periodic review ongoing
- Disclosed root-cause post-mortems for any data-impacting event
No fine-print games
Are you a direct lender or a broker?
Will applying hurt my credit score?
What happens to my data if I don't get funded?
Who has access to my application internally?
Ready when you are.
Apply through one secure workflow. Soft credit for pre-qualification. Any match, offer, decision, or funding timeline comes from the participating provider and is not guaranteed.