Security and data
How your documents are treated
Receipt-provenance honesty.A private result is marked as the unverified-provenance class, visibly distinct from a public SEC-filed receipt — the system says, on its own output, that the source was your private document and not an independent public filing.
No persistence. The bytes live only in memory; nothing is written to disk or blob storage; logs carry counts and states only, never document contents or a filename.
Session isolation. The raw filename is never read; files are handled positionally; only the anonymised borrower label is carried.
Documents are read in memory for the duration of the run and are not written to disk or object storage; the private path has been proven by an automated gate to make zero writes and zero outbound calls. Logs hold counts and states, never document content or figures. There is no login other than the access password for the public screening report; the private path is operated by the founder: a lender sends documents, receives the report, and nothing is retained. The public pages set no cookies. The password-gated screening pages set a session cookie and a usage-quota cookie; neither is a tracking cookie. No analytics script runs. Hosting: Netlify. Encryption in transit: TLS. A SOC 2 report does not exist.