Security

Bank-grade protection for the two things that matter most: your business data and your money.

Controls

How your data is protected

Encryption everywhere

TLS 1.2+ for data in transit and AES-256 for data at rest, including the database and document storage.

Private document storage

Uploaded documents live in private buckets. Access is granted per user through row-level security — never public URLs.

Authentication

Accounts use Supabase Auth with signed JWT sessions. Optional multi-factor authentication for group leaders and admins.

Least-privilege access

Row-Level Security policies mean a user can only read their own profile, their group’s data, and their own documents.

Immutable audit log

Every sensitive action — verification decisions, approvals, disbursements, logins — is written to activity_logs with actor and IP.

Isolated environments

Production is separated from development and test. Secrets are managed outside the codebase and rotated regularly.

Funds segregation

Client balances are held at FDIC-insured partner banks in for-benefit-of accounts, separate from company operating funds.

Monitoring & response

Automated alerting on anomalous activity, sanctions-list hits, and failed-login spikes, with a documented incident runbook.

Program

Ongoing practices

  • Annual third-party penetration testing and continuous dependency scanning.
  • Data minimisation: we collect only what underwriting and regulation require.
  • Documented data-retention schedule; deletion requests honoured where law allows.
  • Vendor review before any third party touches customer data.
  • Role-based staff access with quarterly access reviews.

Reporting a vulnerability

Found something? Email security@cfpartnership.com with steps to reproduce. We acknowledge reports within two business days and do not pursue action against good-faith research.