Due diligence

Security

How the software is hosted, who can reach what, and how it is built and released.

Hosting

  • The software runs on Cloudflare’s network. There is no server of our own to patch or lose.
  • The shared sandbox and our invoicing counts are held in Cloudflare storage placed in Oceania.
  • A lender’s records live in the lender’s own database, in its own account, reached over signed HTTPS. We hold no copy.

Encryption

  • HTTPS only, with HSTS. Nothing is served over plain HTTP.
  • Data at rest is encrypted by the platform it sits on: Cloudflare for ours, the lender’s own provider for its records.
  • Each lender’s records carry a hash chain, so a record changed afterwards fails verification when it is read.

Access

  • API keys are signed (HMAC-SHA256), scoped to one lender and to live or test, expire, and can be revoked. No table of keys exists to steal.
  • Staff sign in with a passkey or a single-use link, emailed to their work address or requested by the lender’s own system. A lender can require passkeys of the staff who record funding. Borrowers sign in with a one-time code or a passkey.
  • Sessions are HttpOnly, Secure and SameSite=Strict cookies. Deactivating a member of staff ends their sessions.
  • Changes to a lender’s controls need a requester and a different approver.
  • Rate limits on every keyed call, lower for test keys and the sandbox.

Pages and browsers

  • A strict content security policy on every page: no inline script, no third-party script except Cloudflare’s cookieless visit counter, no framing.
  • Nothing about a person is ever put in an address, so no link can leak one.

How it is built and released

  • No third-party packages: the source is ours, line by line, so there is no supply chain to compromise.
  • No hosted AI model is called in any credit assessment.
  • More than 6,500 automated tests run before every push and again before every deploy; a failing test stops the release.
  • Every figure the software produces carries the evidence it came from, so a wrong one can be traced.

Reporting a problem

Write to security@creditcresttechnologies.com.au, as security.txt says. We acknowledge within one business day.