Skip to content
Trust Center

Security, privacy, and transparency, documented so you can check it.

SCREDIT is designed for organizations managing credit workflows, receivables operations, and sensitive customer data. This Trust Center gives procurement, security, and business teams a single place to review our legal, privacy, and security posture.

Data ownership

Customer-controlled

Your organization remains the owner of customer, financial, and workflow data submitted into SCREDIT.

Access model

Least privilege

Role-based controls, separation of duties, and audited administrative access are built into the operating model.

Security posture

Security-first

Architecture, monitoring, logging, encryption, and change management are designed to support enterprise reviews.

Trust principles

The SCREDIT trust model combines platform controls, operating discipline, and customer-facing transparency so you can evaluate the product without waiting on a sales call.

Tenant-aware data isolation aligned to your schema-per-tenant platform model.

Encryption in transit and at rest for sensitive platform and business information.

Role-based controls for finance, credit, collections, and administrator personas.

Centralized logging and auditability for privileged actions and core workflow events.

Controlled vendor and integration usage for hosting, email, and bureau data flows.

Documented legal, privacy, and security materials for procurement and customer reviews.

Compliance posture

These materials are designed to support enterprise procurement, security questionnaires, and initial vendor reviews while EFILOS advances its formal compliance roadmap.

Controls designed around SOC 2 principles — a readiness program, not yet a completed third-party audit; we state our status plainly

Certification is on the roadmap, sequenced with our first production customers rather than run against an empty platform — if it is a procurement gate for you, tell us early and we will treat it as one

Privacy-by-design operational practices

Subprocessor and vendor review discipline

Incident response and breach communication planning

Security review support for enterprise procurement teams

Audit trails for sensitive workflow and approval activity

Security posture

Designed for credit and risk teams handling sensitive business data.

SCREDIT supports operational teams that work with application data, trade references, and collections records. The security experience should feel clear, mature, and procurement-ready from the first review.

Each customer's data is held in its own database schema rather than separated by a filter on a shared table — isolation is structural, not a query condition someone has to remember to apply.

Permissions are enforced at the API boundary per action, not only hidden in the interface: read and write are distinct rights, and a request without the right one is refused server-side.

Inbound webhooks from banking and integration providers are signature-verified before the payload is trusted, with unverified delivery disabled in production and that setting checked by an automated build gate.

Documents signed in SCREDIT produce a Certificate of Completion — every signer, the consent they agreed to, timestamps, originating address and device, and a SHA-256 fingerprint of the final document — so an executed guarantee can be evidenced years later.

Identity and access model designed for admin, analyst, approver, collector, and reviewer workflows.

Network and application boundaries designed to support WAF, load balancing, service segmentation, and secure APIs.

Observability model for system health, operational errors, and security-relevant events.

Data handling model for customer accounts, credit applications, financial statements, and external bureau workflows.

Customer resources

The policies and documents a security review asks for.

Access the resources directly through our legal hub so stakeholders can self-serve the materials they need for compliance and legal review.

Continuity

What happens to your data if we are not here.

We are an early-stage company and we would rather answer this directly than let you infer it. Every commitment below is either a matter of public record or an obligation already in our Terms of Service and Data Processing Agreement.

What happens to our data if EFILOS is acquired or shuts down?

Two things bound that risk, and the first matters more than anything we could promise. Your ERP remains the system of record for invoices, payment terms, due dates, and cash application — SCREDIT is the operating layer above it, not a replacement for it. If EFILOS ceased to exist tomorrow, your receivables ledger would be exactly where it is now, in the system you already run. What you would lose is the workflow layer, not your financial records. That is a materially smaller exposure than a platform that becomes your ledger. Second, the Terms of Service and our Data Processing Agreement already commit us to returning or deleting your data on termination at your written request, and that obligation survives a change of control.

Who are we actually contracting with?

EFILOS TECHNOLOGIES, Inc., a corporation formed under the laws of the State of Texas and registered at 3723 Greenville Avenue, STE 60828, Dallas, TX 75206. It is the sole entity that provides SCREDIT: your agreement is with it, your data is processed by it, and no other entity sits between the two. Our terms are governed by Texas law with venue in Dallas County. We would rather you confirmed that than took it on trust — the registration is a matter of public record with the Texas Secretary of State, and if your review needs the certificate of formation, a W-9, or a signed vendor form, ask and we will send them the same day.

You are early-stage. Why is that not a reason to wait?

It is a fair question and we would rather answer it than talk around it. We are founder-led and onboarding a founding cohort, and we are not going to claim a scale we do not have. What we would say is this: the switching cost of SCREDIT is deliberately low because we do not take over your ledger, and founding-partner terms are structured so that early customers are compensated for the risk they are taking rather than charged a premium for being first. If vendor maturity is a hard requirement for your organisation right now, we would rather you told us on the first call than discovered it in month six.

Can we get our data out while we are still a customer?

Yes — this is not only an exit question. Reporting and statement outputs are exportable during normal use, and your data remains yours throughout, as recorded in the Trust Center and the Data Processing Agreement. If your security review requires a specific export format or a documented extraction path, raise it during evaluation and we will answer precisely rather than in principle.

FAQ

Common questions from customer security and procurement teams.

Who owns data stored in SCREDIT?

Customer organizations retain ownership of their business and applicant data. EFILOS operates SCREDIT as the secure software platform used to process that data on the customer’s behalf.

Does SCREDIT support enterprise security reviews?

Yes. The Trust Center, legal package, security whitepaper, architecture diagrams, and compliance artifacts are designed to support customer procurement and security evaluation processes.

How does SCREDIT handle sensitive credit information?

The platform is designed around least-privilege access, tenant-aware isolation, encrypted transport and storage, controlled workflows, and logging for sensitive actions.

Where should customers report security concerns?

The Trust Center provides a direct security contact path so customers, partners, and researchers can raise concerns through a controlled disclosure channel.

Need a direct security review path?

For vendor reviews, security questionnaires, or architecture discussions, direct teams to our controlled trust and legal workflow.