Due diligence
Security
How the software is hosted, who can reach what, and how it is built and released.
Hosting
- The software runs on Cloudflare’s network. There is no server of our own to patch or lose.
- The shared sandbox and our invoicing counts are held in Cloudflare storage placed in Oceania.
- A lender’s records live in the lender’s own database, in its own account, reached over signed HTTPS. We hold no copy.
Encryption
- HTTPS only, with HSTS. Nothing is served over plain HTTP.
- Data at rest is encrypted by the platform it sits on: Cloudflare for ours, the lender’s own provider for its records.
- Each lender’s records carry a hash chain, so a record changed afterwards fails verification when it is read.
Access
- API keys are signed (HMAC-SHA256), scoped to one lender and to live or test, expire, and can be revoked. No table of keys exists to steal.
- Staff sign in with a passkey or a single-use link, emailed to their work address or requested by the lender’s own system. A lender can require passkeys of the staff who record funding. Borrowers sign in with a one-time code or a passkey.
- Sessions are HttpOnly, Secure and SameSite=Strict cookies. Deactivating a member of staff ends their sessions.
- Changes to a lender’s controls need a requester and a different approver.
- Rate limits on every keyed call, lower for test keys and the sandbox.
Pages and browsers
- A strict content security policy on every page: no inline script, no third-party script except Cloudflare’s cookieless visit counter, no framing.
- Nothing about a person is ever put in an address, so no link can leak one.
How it is built and released
- No third-party packages: the source is ours, line by line, so there is no supply chain to compromise.
- No hosted AI model is called in any credit assessment.
- More than 6,500 automated tests run before every push and again before every deploy; a failing test stops the release.
- Every figure the software produces carries the evidence it came from, so a wrong one can be traced.
Reporting a problem
Write to security@creditcresttechnologies.com.au, as security.txt says. We acknowledge within one business day.