Security
Built for sensitive financial data.
Documents are private. Access uses short-lived signed URLs — not public buckets.
Credit is only accessed with permission. Soft and hard inquiries require explicit consent records with version and timestamp.
No hard credit inquiry without affirmative authorization. Consent is never pre-checked.
SSNs and full account numbers are never stored in browser localStorage/sessionStorage. UI masks sensitive identifiers.
API secrets stay server-side. Sensitive endpoints are rate-limited. Audit events track important actions without logging document contents or SSNs.
Row Level Security and role-based access (Borrower / MLO / Admin) are part of the data model for production Supabase/Postgres deployments.