Due diligence
Vendor questionnaire
The questions lenders send first, answered in a line each. Your own form? Send it to hello@creditcresttechnologies.com.au and we will fill it in.
Where is the software hosted?
On Cloudflare’s global network. There is no server of our own.
Is borrower data stored by Creditcrest?
No. It is read in transit; a lender’s records live in the lender’s own database.
Is data encrypted in transit and at rest?
Yes. HTTPS only with HSTS; at rest by the platform holding it.
Can data be processed outside Australia?
It may be: Cloudflare is global, and some suppliers are in the United States and Spain. See Data and suppliers.
Who are your subprocessors?
Listed on Data and suppliers, with what each does and where. 30 days’ notice before a new one.
How are API keys protected?
Signed with HMAC-SHA256, scoped to one lender, live or test, expiring and revocable.
How do staff sign in?
With a passkey, or a single-use link emailed to their work address or requested by the lender’s own system. Deactivating someone ends their sessions. Sessions are HttpOnly, Secure, SameSite=Strict.
Is there multi-person approval for changes?
Yes. A control change needs a requester and a different approver.
Do you use third-party code libraries?
No. The software has no third-party packages.
Do you use AI in credit decisions?
No hosted AI model is called in any assessment, and the software never approves or declines.
How is software tested before release?
More than 6,500 automated tests before every push and every deploy; a failure stops the release.
Can a release be rolled back?
Yes, to the previous release, in minutes.
What is your availability commitment?
99.5% a month, with service credits and a right to terminate.
What are your support hours?
9am–5pm Sydney time on business days; outages worked on at once, in or out of hours.
How quickly are breaches notified?
Within 24 hours of becoming aware, to each affected lender.
Have you had a penetration test?
Not yet. It is done before any lender goes live, and the summary is shared.
Do you hold SOC 2 or ISO 27001?
No, not yet.
Do you hold insurance?
Not yet: professional indemnity and cyber cover are not held.
Are you licensed?
No. Creditcrest is not a credit provider or credit assistance provider; the lender’s licence governs its lending.
Who owns the data?
The lender. Its records are in its own database throughout, and remain readable if Creditcrest stops.
What happens at the end of the contract?
Nothing to return or delete: we hold no borrower data. Invoicing counts are kept seven years for tax.
Can we test before going live?
Yes: the sandbox with invented data, then a shadow run on your real applications beside your own process.
Who holds the credit bureau relationship?
You do. We run the enquiries and monthly reporting on your behalf, under your agreement.
Who is accountable at Creditcrest?
Niral J Shah, founder and credit advisor.