Each tenant is isolated. Every action is on a timeline.

Each customer environment is isolated, and every action is recorded on a timeline. Handlers work from that record.

It sits in front of your existing systems. We do not replace your core.

Where data lives

Hosting and isolation

Hosted in the EU

We run entirely on Microsoft Azure in EU data centers, and all data stays inside the EU at all times.

Encryption everywhere

  • Data encrypted at rest
  • Data encrypted in transit
  • Each customer environment uses its own encrypted vault

Per-tenant isolation

Each customer receives its own acceptance and production databases. No customer data is ever shared or co-located.

All documents uploaded and generated during the process are stored in a secure vault that is protected with a unique environment key.

Who can sign in

Access control

SSO with MFA

Case handlers authenticate through their own or our identity provider. MFA is enforced inside the SSO process.

Portal-level separation

We avoid complex role-based permissions. Each portal is purpose-built for a specific type of user, and everyone inside that portal has the same rights, so permissions stay predictable and configuration risk stays low.

What the timeline records

Application timeline

Every action is recorded on a timeline. Handlers work from that record.

We track:

  • every user action
  • every workflow step
  • every rule evaluation
  • every document generated
  • the full signature cycle
  • identity validation paths
  • credit and sanctions checks
  • how every application was started

SSO logging

Failed login attempts and SSO events are tracked by the customer's identity provider.

Documents in the process

Document security

Controlled generation

Contracts, SEPA mandates, amortization tables, UBO declarations, and supporting documents are automatically generated by the platform. There is no local editing, no manual adjustment, and no version confusion.

Secure storage

  • Documents stored encrypted per case
  • Amortization tables will have multiple versions over time
  • Other documents exist once and are immutable

Retention

When documents are synced to your core or archived in your DMS, they are deleted here within 30 days.
Other process documents: Deleted within 30 days after the case is no longer needed.

How signers are identified

Identity verification

Our default setup makes use of Entrust products: Signhost and Onfido.

Supported methods

  • Scribble
  • Email
  • Phone
  • DigiD
  • iDIN
  • iDeal
  • SurfNet
  • eHerkenning
  • eIDAS
  • itsme (ID and passport)
  • OIDC
  • Onfido (ID and passport)
  • IP validation
  • Consent and CSc flows

How signers are verified

Each signer chooses their preferred method from the organisation's minimum allowed level. For example, iDIN, itsme or Onfido is common in the Netherlands. Onfido and itsme can be used for passport or ID card validation.

The platform validates authentication data against the signer's information. If something does not match (for example, last name differences due to marriage), the case is flagged for handler review. Handlers can approve legitimate variations or decline incorrect signatures.

Screening

KYC, AML, and sanctions screening

Checks we run

  • PEP screening
  • Sanctions (231 global lists updated daily)
  • Basic AML
  • Internal blacklists (optional)

Pass/fail with human review

Each match returns a score. If the score exceeds a threshold, a handler must give an opinion. The system score and the human score are then compared, and outliers can be flagged for additional screening.

How we connect

Integrations and connectivity

There are two kinds of connection, and they stay separate.

This product → Your core systems

We often connect to the customer's core lending or leasing systems. Every core system is different. We support:

  • REST APIs
  • SOAP services
  • Batch handovers
  • Read-only database access (used when a core system exposes no API)
  • Hybrid approaches

We store only the fields required for the workflow. The customer's endpoint controls what is received, and we never save unnecessary fields. Security:

  • Outbound modern TLS-only communication
  • Full audit trail of synchronized data
  • No unsolicited inbound access

Most customers start without or only have minimal core-system integration. Once the process is proven, deeper integrations are added. Full integration takes extra time.

Your partners (vendors, installers, dealers) → this product

Partners can start a self-service flow or submit data directly to us through a secure API.

  • API-key based JWT authentication
  • Rate limits applied
  • Modern TLS enforced
  • Technical logging for all partner interactions

Partner traffic is authenticated and logged.

Boundaries

What we don't do

We sit in front of your existing systems. We do not replace them.

  • We do not run day-to-day financial administration
  • We do not handle any deductions
  • We are not a replacement for core banking systems
  • We offer rule-based credit underwriting for small programmes, not for large bespoke deals.

Need isolation and timeline facts for a risk assessment?

30 minutes on Azure in the EU, per-tenant isolation, and what the timeline records.