Security & privacy

Bank confirmation letter data is sensitive commercial information. These are the controls the product is designed around. This demonstration environment uses fictional data only.

Single-purpose tokens

Applicant and banker links authorize one request and one action. Only cryptographic hashes are stored, never raw tokens.

One-time codes

Sensitive content is hidden until an emailed code is verified. Codes expire in 10 minutes and are never logged or stored in plaintext.

Expiry and revocation

Links default to 14 days and can be shortened, revoked or locked after repeated failures. Every access attempt is recorded.

Tenant isolation

Row Level Security scopes records to active organization membership. One vendor organization can never read another's data.

Least privilege

Salespeople cannot open bank responses, sensitive attachments or private credit notes. Users cannot change their own role.

Private documents

All files live in private storage and are served only through short-lived signed URLs. Account numbers are masked in UI and logs.

Honest verification

A response is only labelled verified when the defined control was completed. Email replies are never auto-verified.

Append-only audit

Status changes, access events, signatures and downloads are written to an audit log that ordinary users cannot edit or delete.

Pre-launch commitments

Privacy impact, threat risk, retention, incident response, malware scanning, penetration testing and Canadian legal review of the authorization, consent and e-signature process are completed before any production use with real businesses.