Last updated: August 2026
CreditDecide is underwriting infrastructure. This policy explains what data we process on your behalf, how it is isolated and protected, and the controls available to you.
CreditDecide processes borrower financial data you submit or pull through connected providers — credit reports, bank transactions, and borrower declarations — solely to produce normalized profiles, risk signals, and underwriting decisions for your organization.
Every record is scoped to your organization and enforced by Row-Level Security at the data layer. No other tenant can read, query, or mutate your data. Sandbox and production environments are fully isolated and never share records or credentials.
Provider credentials (credit bureaus, open banking) you store are encrypted at rest, scoped to your organization, and used only for outbound provider calls. Client secrets are never returned in full by the API and are masked in the dashboard.
API keys are SHA-256 hashed at rest. The full key is shown once at creation or rotation and cannot be recovered. Keys are environment-scoped (sandbox uw_test_ or production uw_live_) and carry granular scopes that limit what each key can do.
You can delete applications, borrowers, and associated data at any time via the API or dashboard. Deleted records are removed from active query results. Audit events are retained to maintain a defensible decision history as required by regulated lending.
We rely on infrastructure and AI providers to run the platform. Data is processed to deliver underwriting intelligence and is not sold or shared for marketing. A current list of sub-processors is available on request.
You control the data in your organization. You may export, correct, or delete records at any time. For data subject requests concerning individual borrowers, coordinate through your organization as the data controller.
Questions about this policy or a data request? Contact us at akinfaks@yahoo.com.