Security & trust

Built for regulated lending.

CreditDecide handles sensitive financial data. Security, isolation, and auditability are designed in from the data layer up — not bolted on.

Tenant isolation

Every record is scoped to an organization. Row-Level Security enforces isolation at the data layer — one tenant can never read or mutate another's data.

Credential vaulting

Provider credentials (Experian, TrueLayer) are stored per-organization and used only for outbound calls. Secrets are never returned in full by the API.

API key security

API keys are SHA-256 hashed at rest; the full key is shown once at creation. Keys are environment-scoped (sandbox vs production) with granular scopes.

Audit trail

Every request carries a request_id and is logged with actor, endpoint, and outcome — giving lenders a defensible record of who decided what, and why.

Environment isolation

Sandbox and production data never mix. Test with synthetic data, then promote to live with a production key and your own provider credentials.

Explainable decisions

Each recommendation is backed by an evidence graph — every risk signal traces to its source document and confidence score. No black-box overrides.

Responsible AI & underwriting governance

AI that shows its work — not just its answer.

Because CreditDecide supports credit decisions, every recommendation is policy-first, evidence-referenced, and fully auditable. No black-box overrides.

01

Policy-first decisions

Lender policy is evaluated before any AI recommendation — the AI never silently overrides policy.

02

Evidence provenance

Every risk signal traces back to its source document, field, and confidence score through the evidence graph.

03

Explainable recommendations

Recommendations ship with a referenced memo — positive signals, risk factors, and the policy outcome that informed them.

04

Human review

Signals that breach policy thresholds route to a human underwriter for review before a final decision is made.

05

Override reasons

When a final decision differs from the recommendation or policy, an override reason is required and recorded.

06

Audit trail

Every decision — automated or human — is logged with actor, timestamp, policy version, and outcome.

07

Outcome monitoring

Post-decision outcomes feed back into calibration, so policies and models improve against real repayment behaviour.

“AI shouldn't just make a decision. It should show why the decision was made, what evidence supported it, which policy was applied, and who ultimately approved or overrode it.”
CreditDecide · Responsible underwriting principle

Security & compliance roadmap

Encryption at rest & in transitImplemented
RBAC & organization-level access controlsShipped
API key hashing & credential protectionShipped
Audit trail & immutable decision historyShipped
Tenant isolation & RLSShipped
Sandbox / production isolationShipped
Data retention & deletion controlsImplemented
GDPR controls & DPAImplemented
Data residency / cross-border data controlsRoadmap
SOC 2 Type IIn progress
SOC 2 Type IIRoadmap
ISO 27001Future roadmap

Need a security review?

We work with lenders and fintechs on data processing agreements, penetration testing, and onboarding reviews. Start building in the sandbox, then request a security package when you're ready for production.

CreditDecide

AI-native underwriting and credit decisioning for modern lenders. Automate applications, configure policies, and make smarter, explainable decisions — anywhere in the world.

No-codeAI-assistedMulti-market

© 2026 CreditDecide

No-code underwriting · AI-assisted risk analysis · Policy engine · Evidence lineage · Reporting & exports

🌍Built for modern lenders across the United States, United Kingdom & AfricaThe underwriting operating system — go.
Our HQ·San Francisco·London·Lagos·Nairobi