Skip to content
Security

How SCREDIT protects credit and financial data.

Schema-per-tenant isolation, role-based access control and a least-privilege runtime, with controls designed around SOC 2 principles — a readiness program, not a completed third-party audit. This page and the Trust Center document exactly what that means, including what we have not done yet.

Core protection model

Our model combines architectural platform controls, rigorous operational processes, and customer-facing transparency.

Encrypted data transport and storage patterns.

Controlled access via RBAC and audited administrative workflows.

Tenant-aware architecture ensuring schema-level data separation.

Multi-layered monitoring and centralized observability.

Change management and peer-reviewed release discipline.

Secure vendor boundaries for cloud hosting and data providers.

Security operations

Operational discipline is the backbone of our trust model, ensuring every release and action is audited and secure.

Continuous monitoring of availability and security events.

Incident response plan for detection, containment, and communication.

Backup and recovery readiness for business continuity.

Vulnerability remediation and dependency management.

Security review support for enterprise procurement.

Centralized identity management and token-based authentication.

Architecture

Visual security architecture for platform and data flow.

High-level platform security architecture

Edge, identity, and data layers that frame the SCREDIT operating model.

Users
CDN / WAF
Identity/Auth
APIs
Isolated DB

Identity and access

Token-based authentication and role-aware permission enforcement.

Secure Login
Token Issuance
API Authorization Check
Workflow Privilege Enforcement

Data isolation

Schema-per-tenant model ensures strict customer data boundaries.

Tenant Schemas
Search Isolation
Storage Boundaries
Disclosure

Responsible disclosure and security review.

We welcome partnership with security researchers and enterprise procurement teams for thorough platform evaluation.

Running a vendor security review? Start with the security review pack — entity, isolation, access control, testing, compliance status and the full legal set on one forwardable page.

Security contact

security@efilostech.com