Everything your security reviewer needs, on one page.
Most vendor security reviews start with a questionnaire and three weeks of email. This page exists so yours can start with a link instead. It is written for the person who has to sign off on SCREDIT, not for the person buying it — so it states what we do, how it is enforced, and what we have not done yet.
Send it on. There is no form, no gate, and nothing here we would not repeat on a call.
What you can settle from this page
Answerable without contacting us.
Who you are contracting with, and under which law
How customer data is separated between tenants
How access is granted, enforced, and recorded
What our AI does, and what it is never allowed to do
How we test the platform, and what testing we have not done
Our compliance status, stated exactly
What happens to your data if we are acquired or shut down
The full legal pack — DPA, Terms, Privacy, Applicant Privacy
What is not here yet, and why
We would rather you saw the gaps listed than found them.
- Data residency statement
- Not published. We will not state where every byte lives until it is verified against the production environment rather than inferred, and we would rather leave the gap visible than fill it with something we cannot stand behind.
- Sub-processor list
- Drafted and short — three parties, with identity and messaging held in-house rather than outsourced. It publishes once residency is confirmed, because the two belong on the page together.
- Completed CAIQ Lite
- In progress against CAIQ Lite v4.1. When it publishes it will be complete, not partial: a questionnaire with blanks is read at the blanks.
- Independent penetration test
- Not commissioned. See the testing section below — we run our own scanning and do not present it as a substitute.
Who you are contracting with, and what happens if we are not here.
What happens to our data if EFILOS is acquired or shuts down?
Two things bound that risk, and the first matters more than anything we could promise. Your ERP remains the system of record for invoices, payment terms, due dates, and cash application — SCREDIT is the operating layer above it, not a replacement for it. If EFILOS ceased to exist tomorrow, your receivables ledger would be exactly where it is now, in the system you already run. What you would lose is the workflow layer, not your financial records. That is a materially smaller exposure than a platform that becomes your ledger. Second, the Terms of Service and our Data Processing Agreement already commit us to returning or deleting your data on termination at your written request, and that obligation survives a change of control.
Who are we actually contracting with?
EFILOS TECHNOLOGIES, Inc., a corporation formed under the laws of the State of Texas and registered at 3723 Greenville Avenue, STE 60828, Dallas, TX 75206. It is the sole entity that provides SCREDIT: your agreement is with it, your data is processed by it, and no other entity sits between the two. Our terms are governed by Texas law with venue in Dallas County. We would rather you confirmed that than took it on trust — the registration is a matter of public record with the Texas Secretary of State, and if your review needs the certificate of formation, a W-9, or a signed vendor form, ask and we will send them the same day.
You are early-stage. Why is that not a reason to wait?
It is a fair question and we would rather answer it than talk around it. We are founder-led and onboarding a founding cohort, and we are not going to claim a scale we do not have. What we would say is this: the switching cost of SCREDIT is deliberately low because we do not take over your ledger, and founding-partner terms are structured so that early customers are compensated for the risk they are taking rather than charged a premium for being first. If vendor maturity is a hard requirement for your organisation right now, we would rather you told us on the first call than discovered it in month six.
Can we get our data out while we are still a customer?
Yes — this is not only an exit question. Reporting and statement outputs are exportable during normal use, and your data remains yours throughout, as recorded in the Trust Center and the Data Processing Agreement. If your security review requires a specific export format or a documented extraction path, raise it during evaluation and we will answer precisely rather than in principle.
How data is separated, and how access is enforced.
Each item below names the mechanism, not the intention. Where a control is enforced by something automatic, we say what enforces it.
Each customer's data is held in its own database schema rather than separated by a filter on a shared table — isolation is structural, not a query condition someone has to remember to apply.
Permissions are enforced at the API boundary per action, not only hidden in the interface: read and write are distinct rights, and a request without the right one is refused server-side.
Inbound webhooks from banking and integration providers are signature-verified before the payload is trusted, with unverified delivery disabled in production and that setting checked by an automated build gate.
Documents signed in SCREDIT produce a Certificate of Completion — every signer, the consent they agreed to, timestamps, originating address and device, and a SHA-256 fingerprint of the final document — so an executed guarantee can be evidenced years later.
Identity and access model designed for admin, analyst, approver, collector, and reviewer workflows.
Network and application boundaries designed to support WAF, load balancing, service segmentation, and secure APIs.
Observability model for system health, operational errors, and security-relevant events.
Data handling model for customer accounts, credit applications, financial statements, and external bureau workflows.
Environment separation
Production and demonstration environments run in separate cloud accounts, not merely separate networks within one account. The boundary is the account itself, so a misconfiguration in the demo environment cannot reach production data.
How the platform is tested — and what we have not tested.
Static analysis (SAST)
SonarQube
Source is analysed for defects and security patterns.
Dependency scanning (SCA)
Snyk
Third-party packages are checked for known vulnerabilities.
Dynamic testing (DAST)
OWASP ZAP · Burp Suite
The running application is tested from the outside.
We have not commissioned an independent third-party penetration test. Our own scanning is not a substitute for one and we will not present it as such. We will commission an external test as we onboard production customers — and if an independent test is a procurement requirement for you, tell us early and we will treat it as one.
Compliance status
Stated exactly as it is. The same wording appears on the Trust Center and in the Security Overview; if you find it phrased differently anywhere, tell us and we will fix it.
Controls designed around SOC 2 principles — a readiness program, not yet a completed third-party audit; we state our status plainly
Certification is on the roadmap, sequenced with our first production customers rather than run against an empty platform — if it is a procurement gate for you, tell us early and we will treat it as one
Privacy-by-design operational practices
Subprocessor and vendor review discipline
Incident response and breach communication planning
Security review support for enterprise procurement teams
Audit trails for sensitive workflow and approval activity
Trust principles
The operating commitments the controls above are built to serve.
Tenant-aware data isolation aligned to your schema-per-tenant platform model.
Encryption in transit and at rest for sensitive platform and business information.
Role-based controls for finance, credit, collections, and administrator personas.
Centralized logging and auditability for privileged actions and core workflow events.
Controlled vendor and integration usage for hosting, email, and bureau data flows.
Documented legal, privacy, and security materials for procurement and customer reviews.
The full legal and governance pack.
All ungated. Attach whichever your process needs.
AI Governance
What SCREDIT’s AI does and does not do: the decision stays deterministic, data is masked before any model call, and nothing sends without human approval.
Security Whitepaper
Overview of SCREDIT architecture, platform safeguards, encryption, logging, and operational security practices.
Privacy Policy
How EFILOS collects, uses, stores, and protects platform and website data across SCREDIT experiences.
Data Processing Agreement
Controller-processor responsibilities for enterprise customers using SCREDIT to process business and applicant data.
Applicant Privacy Notice
Applicant-facing notice for organizations collecting credit applications, references, and financial data through SCREDIT.
Terms of Service
Use terms covering platform access, lawful use, service boundaries, intellectual property, and account responsibilities.
Cookie Policy
Website cookie and analytics disclosure suitable for EFILOS marketing and product web properties.
What to ask us for
Certificate of formation, a W-9, a signed vendor form, or a completed copy of your own security questionnaire — ask and you will have them the same day. If your review gates on something we have listed above as missing, tell us early and we will treat it as a gate rather than a preference.