Compliance & Security

Last updated: January 2025

Security Infrastructure

Creditey implements comprehensive security measures to protect financial data:

  • 256-bit Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
  • Access Controls: Role-based access control (RBAC) with multi-factor authentication for administrative access
  • Audit Logging: Comprehensive logging of all data access, modifications, and system events
  • Security Monitoring: 24/7 automated monitoring for suspicious activity and security threats
  • Vulnerability Management: Regular security assessments and prompt patching of identified vulnerabilities
  • Data Isolation: Practice data is logically separated and access is strictly controlled via unique access codes

Regulatory Compliance

Financial Regulations: Our payment reporting services operate in accordance with financial industry standards including fair lending practices, data accuracy requirements, and consumer protection laws.

Data Protection: We comply with applicable data protection regulations including state privacy laws (CCPA, CPRA) and maintain data processing agreements with all third-party vendors.

Note on HIPAA: Our services analyze business payment data only (vendors, payroll, rent, utilities). We do not collect, process, or store protected health information (PHI) or patient data, therefore HIPAA does not apply to our operations.

Data Retention & Deletion

Report Access: Issued reports and their evidence manifests remain accessible to the receiving lender in the Lender Portal for the contracted retention period, with a standard term of 84 months. Access is not time-limited to a purchase window and does not require repurchase.

Credeity Financial Records: Payment transaction records, invoices, and financial audit trails are retained for 7 years to comply with financial recordkeeping requirements. This period applies to Credeity's own accounting records and is separate from the retention of borrower findings and evidence.

Practice Data: Practices and businesses can request deletion of their payment data at any time. Deletion requests are processed within 30 days, though previously purchased reports will remain accessible to lenders for their retention period.

Account Deletion: Users can request account deletion at any time. Upon deletion, personal information is removed within 30 days, except for records required for legal or regulatory compliance.

Findings, Source Documents, and Derived Transaction Data: Findings, verification statuses, evidence citations, the Case Evidence Manifest, and the methodology version in force at issuance are retained for the contracted retention period, with a standard term of 84 months to align with lender credit file retention and SBA guaranty purchase review windows. Source documents (including original bank-statement PDFs and accounting-file uploads) are delivered to the lender with the report and are retained by Credeity for 90 days after delivery, then deleted. The lender is the system of record for source documents from issuance forward. A lender may elect extended Credeity custody of source documents up to the findings retention term. Derived transaction data, meaning structured extracts parsed from bank statements such as date, description, debit, credit, account, and running balance, are retained for the same contracted findings retention term and are not deleted when the source PDF is deleted. Derived transaction data are not findings. They are retained so that a finding remains reproducible from its inputs after the source document window closes. All deletions are logged, and a deletion certificate is available to the lender or borrower on request.

Access Control & Authorization

Practice Control: Practices and businesses maintain full control over who can access their payment reports through unique access code generation and management. Access codes can be revoked at any time.

Lender Authorization: Lenders must possess a valid access code provided directly by the practice to view reports. All report access is logged with timestamps and lender identification for audit purposes.

Internal Access: Creditey employees have strictly limited access to customer data. Access is granted only when necessary for support, security, or legal compliance purposes, and all access is logged.

Third-Party Service Providers

We work with vetted third-party providers for essential services including payment processing, cloud infrastructure, and security monitoring. All vendors are required to maintain appropriate security standards and sign data processing agreements. We do not share data with marketing or advertising platforms.

Incident Response

In the event of a security incident that may affect customer data, we will notify affected users within 72 hours of discovery and provide details on the nature of the incident, data affected, and remediation steps taken. We maintain an incident response plan and conduct regular security drills.

Ongoing Compliance Efforts

We continuously evaluate and improve our security and compliance practices to meet evolving industry standards.

Questions & Reports

For compliance questions or to report security concerns, contact us at:
Email: security@creditey.com
For urgent security matters, mark the subject line as "URGENT SECURITY ISSUE"