TRUST AND SECURITY

Built to pass your vendor review before the first case.

Credeity was founded by a CPA who also holds CISSP and CISA credentials. Security and auditability are not features added later. They are how the company was designed.

Regulatory positioning

Credeity reports are prepared at the request of the lender with the written authorization of the borrower, for use in a specific commercial credit decision. Credeity is not a consumer reporting agency and does not compile or sell consumer reports.

Fair lending

Credeity is not a substitute for a lender's fair lending obligations and does not reduce them.

Because the Payment Discipline Index is deterministic. The score is the on-time rate minus published per-occurrence late penalties by tier and severity, with fixed score floors when conditions are met. A lender's compliance team can recompute it from the same inputs. Scoring conventions in force at issuance are stated in each report and on the Methodology and Model Documentation page. Credeity does not use configurable scoring weights or lender-configurable floors.

Credeity does not use race, ethnicity, national origin, sex, age, or any proxy for a prohibited basis as a scoring input. Reports disclose payor concentration alongside the Payment Discipline Index, because practices with higher Medicaid concentration collect more slowly, which can affect payables timing independent of management quality. The two are intended to be read together rather than in isolation.

Absence of evidence is not treated as evidence of nonpayment. Where records are incomplete, obligations are reported as Not Tested or Unable to Verify and are excluded from scoring rather than scored as late.

FCRA and data sourcing

Borrower financial records are provided under borrower authorization. Credeity separately obtains applicable authoritative-source records directly as part of the verification scope. Credeity does not access borrower bank or tax accounts directly today.

Credeity operates outside the FCRA consumer reporting framework because it analyzes borrower-authorized accounting exports from the practice's own business records rather than consumer credit data or transaction-pull services. Borrower-provided accounting data is corroborated against actual bank debits before the report is issued.

Supporting Lender Decision Documentation

Credeity provides verification findings and supplemental analytics. It does not make or recommend a credit decision. Credeity does not make credit decisions, does not recommend approval or decline, and is not a consumer reporting agency. The lender remains the decision-maker at every step.

What Credeity does provide is evidence a lender can document. Every finding in an Evidence Report carries a clear status (Match, Partial Match, Variance, Unable to Verify, or Not Tested) and a named evidence source. Findings are produced by a rules-based analysis engine, not AI-generated conclusions, so the same inputs always produce the same findings and every finding can be traced to its underlying evidence.

When a lender declines a file, downgrades terms, or documents an exception, examiners and internal credit policy expect plain-English reasons. Credeity report findings are designed to translate directly into documentable reason classes, for example:

  • Variances between borrower-provided financials and lender-obtained IRS Form 941 transcript information correspond to the reason class "tax transcript discrepancies."
  • Irregular timing between collections, payables, and tax obligations corresponds to the reason class "operating cash flow inconsistency."
  • Licensing records that do not corroborate correspond to the reason class "licensing gaps or unverifiable license status."

Credeity provides source-linked findings that the lender can use when documenting its own credit rationale.

Corroborated evidence in. Documentable reasons out. The decision stays with the lender.

Why Credeity Deploys Faster

Cash flow underwriting is transforming consumer lending, and the same shift is now reaching commercial credit. The difference is how much infrastructure it usually takes to get there.

A traditional cash flow underwriting project typically requires:

  • Loan origination system (LOS) integration before first value
  • Core banking integration to reach account-level data (on-us data)
  • New vendor data pipelines and categorization tuning
  • Months of implementation before the first underwriter benefits

Credeity requires:

  • Borrower authorization
  • Independent verification against external, borrower-authorized evidence sources (off-us data)
  • Delivery of a complete Evidence Report and Analytics Supplement to the credit team
  • No underwriting model replacement, no core integration, no system overhaul

Credeity operates as a standalone verification layer (second-look underwriting) that sits alongside a lender's existing process. It adds an independent evidence source (dual-source underwriting) without displacing spreads, bureau data, or credit policy. A lender can put Credeity in front of a live file this quarter, not next year.

For lenders that later want systematic delivery, a documented integration path is available. See the LOS Integration Plan, available on request. Integration is an option, never a prerequisite.

How borrower data moves through Credeity

1. Authorization.

The borrower signs a written authorization before any data is collected. No data is received or analyzed without it.

2. Encrypted upload.

Accounting exports and bank statements are transmitted over TLS and encrypted at rest.

3. Analysis.

Data is processed inside a controlled environment. Access is limited to the analysts assigned to the case.

4. Delivery.

Reports are released through the Lender Portal under dual control. No report leaves the system without a second review.

5. Retention and deletion.

Findings, verification statuses, evidence citations, the Case Evidence Manifest, and the methodology version in force at issuance are retained for the contracted retention period, with a standard term of 84 months to align with lender credit file retention and SBA guaranty purchase review windows. Source documents (including original bank-statement PDFs and accounting-file uploads) are delivered to the lender with the report and are retained by Credeity for 90 days after delivery, then deleted. The lender is the system of record for source documents from issuance forward. A lender may elect extended Credeity custody of source documents up to the findings retention term. Derived transaction data, meaning structured extracts parsed from bank statements such as date, description, debit, credit, account, and running balance, are retained for the same contracted findings retention term and are not deleted when the source PDF is deleted. Derived transaction data are not findings. They are retained so that a finding remains reproducible from its inputs after the source document window closes. All deletions are logged, and a deletion certificate is available to the lender or borrower on request.

What we never do

Credeity does not sell borrower data, use borrower information outside the authorized engagement, or share borrower information except as required to perform the authorized service and deliver results to the authorizing lender. Access to external records occurs only under documented borrower authorization or another permitted basis.

Every report distinguishes borrower-provided evidence from evidence obtained directly by Credeity, and states the acquisition method for every account.

Subprocessors

ProviderFunctionLocation
Supabasedatabase and storageUnited States
Vercelapplication hostingUnited States

Compliance roadmap

Credeity operates against a control set aligned to SOC 2 Trust Services Criteria. A formal SOC 2 Type II examination is on the company roadmap. Lenders may request our security whitepaper and completed due diligence questionnaire at any time.

If a finding is disputed, see the Findings Correction Policy.