Every report, every SSN, every account number is handled with the same care you'd expect from a bank, because that's exactly the kind of data it is.
Client data is stored on infrastructure independently audited to SOC 2 Type II and ISO/IEC 27001 standards, the same level of certification banks and healthcare platforms are held to.
Only the people you explicitly grant access to can see a given client's file, enforced at the platform level, not just policy.
Every action taken on a client's file, by you, your staff, or the platform, is logged and reviewable.
A closer look, for you and for the clients who ask.
Credit report data and client PII are encrypted at rest and in transit, and stored on infrastructure that holds SOC 2 Type II and ISO/IEC 27001 certification, independently audited on a recurring basis. Data never lives on local devices.
Team and Enterprise plans let you assign role-based permissions, so staff only see the client files relevant to their work.
Account and client data is retained for as long as an account is active, and for 90 days after cancellation to allow for data export, after which it is permanently deleted.
Dispute letters are transmitted through a secure, monitored mail provider chain, tracked from send to delivery.
This page is written so you can point your own clients to it when they ask how their information is protected.