KreediteSecurity
Security & Data Posture

Consent first. Encryption throughout. Retention on purpose.

Kreedite scores lending decisions on data borrowers have consented to share with a specific lender for a specific purpose. Everything below describes what we do today - stated honestly, without inflating a certification we do not yet hold.

Reference instrument
  • Encryption in transitTLS 1.2+ enforced
  • Encryption at restAES-256
  • Consent scopePer source, per applicant
Data handling

What is stored, for how long, and who can see it.

Encryption in transit and at rest

All signal ingestion moves over TLS 1.2 or higher with certificate pinning where the source supports it. Data at rest is encrypted with AES-256 keys held in a dedicated key management service.

Least-privilege access scope

Access to raw signal data is scoped to the specific service accounts that need it for scoring. No engineer has default read access to production data - elevated access is short-lived and audited.

Retention on purpose

Signal data is retained only for as long as it is needed to score, defend and reproduce a lending decision. Retention windows are agreed with the lender per deployment - defaults are conservative, not maximal.

Consent revocation

A borrower can revoke consent for any signal source. Revocation blocks future reads. Past scored decisions retain a full audit trail of which sources were active at the time of scoring.

Recommendation - not decree

Kreedite provides a composite score and a recommendation tier. The lending decision itself always remains with the institution's own credit policy and human review. The engine is decision support, not the decision maker.

  • Encryption in transitTLS 1.2 or higher
  • Encryption at restAES-256
  • Access modelLeast-privilege, audited
  • Consent surfacePer source, per applicant
  • Retention defaultConservative, deployment-specific
  • Deployment optionsManaged, VPC, or on-prem (Enterprise)
Compliance posture

What is in place today. What is being built. Nothing else.

Fintech vendor claims often quietly outrun their actual controls. We refuse that habit - the paragraphs below describe what is operationally true today, not what a future certification might allow us to claim.

In place
Operational controls

Encryption in transit and at rest, least-privilege access, audit logging of production data reads, quarterly access reviews, and separation of duties between engineering and production access.

In place
Consent framework

Every signal source is bound to a specific, revocable consent captured at the point of applicant onboarding, stored per applicant, per source, per lender.

In place
Auditability

Every scored decision retains its signal set, sub-scores, weights, model version and rule version - reproducible and defensible years after the decision.

In progress
Formal certifications

Recognized third-party attestations for information security are being progressed. We will state the specific standard and its issue date on this page only after certification lands - not before.

In progress
Applicant-facing disclosures

Standardized applicant-facing explanations of what signals were used are being extended across additional markets and languages, subject to local regulatory requirements.

Not claimed
Universal certifications

Kreedite does not claim jurisdiction-agnostic compliance. Every deployment scopes to the specific data-protection and lending regulations of the market it serves.

What we deliberately do not do

A short list, honestly kept.

  • We do not read data the borrower has not explicitly consented to share.
  • We do not use protected attributes (identity characteristics, demographic categories) as scoring inputs.
  • We do not auto-approve or auto-decline - the lending decision is always the institution's.
  • We do not silently penalize missing signals - weights re-normalize across the sources actually present.
  • We do not sell borrower data to any third party under any commercial arrangement.
Next step
Walk through our data handling with your CISO.

A working session with our engineering lead and yours - controls, retention, and consent scope.