SmallTicketSolutions is designed to run critical financial workflows. We protect applicant data, enforce your rules, and create a complete audit trail across every action, document, and decision.
Our approach is simple: use proven technology, apply strict separation, validate every step, and never rely on guesswork.
How we keep your data secure
Data security
Hosted in the EU
We run entirely on Microsoft Azure in EU data centers. All data stays inside the EU at all times.
Encryption everywhere
Data encrypted at rest
Data encrypted in transit
Each customer environment uses its own encrypted vault
Per-tenant isolation
Each customer receives its own acceptance and production databases. No customer data is ever shared or co-located.
All documents uploaded and generated during the process are stored in a secure vault that is protected with a unique environment key.
How we keep your data private
Access control
SSO with MFA
Case handlers authenticate through their own or our identity provider. MFA is enforced inside the SSO process.
Portal-level separation
We avoid complex role-based permissions. Each portal is purpose-built for a specific type of user, and everyone inside that portal has the same rights. This keeps permissions predictable and reduces configuration risk.
Know exactly what happened
Audit trail
We maintain a complete audit trail for everything that happens in the system.
We track:
every user action
every workflow step
every rule evaluation
every document generated
the full signature cycle
identity validation paths
credit and sanctions checks
how every application was started
SSO logging
Failed login attempts and SSO events are tracked by the customer's identity provider.
All about the documents inside the process
Document security
Controlled generation
Contracts, SEPA mandates, amortization tables, UBO declarations, and supporting documents are automatically generated by the Platform. No local editing. No manual adjustments are possible. No version confusion.
Secure storage
Documents stored encrypted per case
Amortization tables will have multiple versions over time
Other documents exist once and are immutable
Retention
For Application to Booking customers: Documents are deleted within 30 days after they are synced with the core system or archived in the DMS. Other process documents: Deleted within 30 days after the case is no longer needed.
Verifying that someone is who they claim to be
Identity verification
Our default setup makes use of Entrust products: Signhost and Onfido.
Supported methods
Scribble
Email
Phone
DigiD
iDIN
iDeal
SurfNet
eHerkenning
eIDAS
itsme (ID and passport)
OIDC
Onfido (ID and passport)
IP validation
Consent and CSc flows
How signers are verified
Each signer chooses their preferred method from the organisation's minimum allowed level. For example, iDIN, itsme or Onfido is common in the Netherlands. Onfido and itsme can be used for passport or ID card validation.
The platform validates authentication data against the signer's information. If something does not match (for example, last name differences due to marriage), the case is flagged for handler review. Handlers can approve legitimate variations or decline incorrect signatures.
Making sure you do business with the right customers
KYC, AML, and sanctions screening
Checks we run
PEP screening
Sanctions (231 global lists updated daily)
Basic AML
Internal blacklists (optional)
Pass/fail with human review
Each match returns a score. If the score exceeds a threshold, a handler must give an opinion. System score and human score are compared. Outliers can be flagged for additional screening.
How we connect to you and to your partners
Integrations and connectivity
We support two types of integrations, and keep them separate so each remains secure, simple, and fully auditable.
SmallTicketSolutions → Your core systems
We often connect to the customer's core lending or leasing systems. Every core system is different. We support:
REST APIs
SOAP services
File-based handovers
Read-only database access (used when a core system exposes no API)
Hybrid approaches
We store only the fields required for the workflow. The customer's endpoint controls what is received. We never save unnecessary fields. Security:
Outbound modern TLS-only communication
Full audit trail of synchronized data
No unsolicited inbound access
Most customers start without or only have minimal core-system integration. Once the process is proven, deeper integrations are added in a controlled and secure way.
Your partners (vendors, installers, dealers) → SmallTicketSolutions
Partners can start a self-service flow or submit data directly to us through a secure API.
API-key based JWT authentication
Rate limits applied
Modern TLS enforced
Technical logging for all partner interactions
This ensures partner traffic is controlled, authenticated, and fully auditable.
Just making sure we're on the same page
What we don't do
To keep processes safe and predictable, we are clear about our boundaries:
We do not run day-to-day financial administration
We do not handle any deductions
We are not a replacement for core banking systems
We offer rule-based credit underwriting for small programs, not for large bespoke deals
We are built for structured, repeatable files, typically up to about one to two million euros when the process is still rules-based. Bespoke committee theatre is a different product.
See how our approach fits your requirements?
If you want a deeper look at our architecture or need support for a risk assessment: