Each tenant is isolated. Every action is on a timeline.
Each customer environment is isolated, and every action is recorded on a timeline. Handlers work from that record.
It sits in front of your existing systems. We do not replace your core.
Each customer environment is isolated, and every action is recorded on a timeline. Handlers work from that record.
It sits in front of your existing systems. We do not replace your core.
Where data lives
We run entirely on Microsoft Azure in EU data centers, and all data stays inside the EU at all times.
Each customer receives its own acceptance and production databases. No customer data is ever shared or co-located.
All documents uploaded and generated during the process are stored in a secure vault that is protected with a unique environment key.
Who can sign in
Case handlers authenticate through their own or our identity provider. MFA is enforced inside the SSO process.
We avoid complex role-based permissions. Each portal is purpose-built for a specific type of user, and everyone inside that portal has the same rights, so permissions stay predictable and configuration risk stays low.
What the timeline records
Every action is recorded on a timeline. Handlers work from that record.
Failed login attempts and SSO events are tracked by the customer's identity provider.
Documents in the process
Contracts, SEPA mandates, amortization tables, UBO declarations, and supporting documents are automatically generated by the platform. There is no local editing, no manual adjustment, and no version confusion.
When documents are synced to your core or archived in your DMS, they are deleted here within 30 days.
Other process documents: Deleted within 30 days after the case is no longer needed.
How signers are identified
Our default setup makes use of Entrust products: Signhost and Onfido.
Each signer chooses their preferred method from the organisation's minimum allowed level. For example, iDIN, itsme or Onfido is common in the Netherlands. Onfido and itsme can be used for passport or ID card validation.
The platform validates authentication data against the signer's information. If something does not match (for example, last name differences due to marriage), the case is flagged for handler review. Handlers can approve legitimate variations or decline incorrect signatures.
Screening
Each match returns a score. If the score exceeds a threshold, a handler must give an opinion. The system score and the human score are then compared, and outliers can be flagged for additional screening.
How we connect
There are two kinds of connection, and they stay separate.
We often connect to the customer's core lending or leasing systems. Every core system is different. We support:
We store only the fields required for the workflow. The customer's endpoint controls what is received, and we never save unnecessary fields. Security:
Most customers start without or only have minimal core-system integration. Once the process is proven, deeper integrations are added. Full integration takes extra time.
Partners can start a self-service flow or submit data directly to us through a secure API.
Partner traffic is authenticated and logged.
Boundaries
We sit in front of your existing systems. We do not replace them.
30 minutes on Azure in the EU, per-tenant isolation, and what the timeline records.