Security and compliance built into every step

SmallTicketSolutions is designed to run critical financial workflows. We protect applicant data, enforce your rules, and create a complete audit trail across every action, document, and decision.

Our approach is simple: use proven technology, apply strict separation, validate every step, and never rely on guesswork.

How we keep your data secure

Data security

Hosted in the EU

We run entirely on Microsoft Azure in EU data centers. All data stays inside the EU at all times.

Encryption everywhere

  • Data encrypted at rest
  • Data encrypted in transit
  • Each customer environment uses its own encrypted vault

Per-tenant isolation

Each customer receives its own acceptance and production databases. No customer data is ever shared or co-located.

All documents uploaded and generated during the process are stored in a secure vault that is protected with a unique environment key.

How we keep your data private

Access control

SSO with MFA

Case handlers authenticate through their own or our identity provider. MFA is enforced inside the SSO process.

Portal-level separation

We avoid complex role-based permissions. Each portal is purpose-built for a specific type of user, and everyone inside that portal has the same rights. This keeps permissions predictable and reduces configuration risk.

Know exactly what happened

Audit trail

We maintain a complete audit trail for everything that happens in the system.

We track:

  • every user action
  • every workflow step
  • every rule evaluation
  • every document generated
  • the full signature cycle
  • identity validation paths
  • credit and sanctions checks
  • how every application was started

SSO logging

Failed login attempts and SSO events are tracked by the customer's identity provider.

All about the documents inside the process

Document security

Controlled generation

Contracts, SEPA mandates, amortization tables, UBO declarations, and supporting documents are automatically generated by the Platform. No local editing. No manual adjustments are possible. No version confusion.

Secure storage

  • Documents stored encrypted per case
  • Amortization tables will have multiple versions over time
  • Other documents exist once and are immutable

Retention

For Application to Booking customers: Documents are deleted within 30 days after they are synced with the core system or archived in the DMS.
Other process documents: Deleted within 30 days after the case is no longer needed.

Verifying that someone is who they claim to be

Identity verification

Our default setup makes use of Entrust products: Signhost and Onfido.

Supported methods

  • Scribble
  • Email
  • Phone
  • DigiD
  • iDIN
  • iDeal
  • SurfNet
  • eHerkenning
  • eIDAS
  • itsme (ID and passport)
  • OIDC
  • Onfido (ID and passport)
  • IP validation
  • Consent and CSc flows

How signers are verified

Each signer chooses their preferred method from the organisation's minimum allowed level. For example, iDIN, itsme or Onfido is common in the Netherlands. Onfido and itsme can be used for passport or ID card validation.

The platform validates authentication data against the signer's information. If something does not match (for example, last name differences due to marriage), the case is flagged for handler review. Handlers can approve legitimate variations or decline incorrect signatures.

Making sure you do business with the right customers

KYC, AML, and sanctions screening

Checks we run

  • PEP screening
  • Sanctions (231 global lists updated daily)
  • Basic AML
  • Internal blacklists (optional)

Pass/fail with human review

Each match returns a score. If the score exceeds a threshold, a handler must give an opinion. System score and human score are compared. Outliers can be flagged for additional screening.

How we connect to you and to your partners

Integrations and connectivity

We support two types of integrations, and keep them separate so each remains secure, simple, and fully auditable.

SmallTicketSolutions → Your core systems

We often connect to the customer's core lending or leasing systems. Every core system is different. We support:

  • REST APIs
  • SOAP services
  • File-based handovers
  • Read-only database access (used when a core system exposes no API)
  • Hybrid approaches

We store only the fields required for the workflow. The customer's endpoint controls what is received. We never save unnecessary fields. Security:

  • Outbound modern TLS-only communication
  • Full audit trail of synchronized data
  • No unsolicited inbound access

Most customers start without or only have minimal core-system integration. Once the process is proven, deeper integrations are added in a controlled and secure way.

Your partners (vendors, installers, dealers) → SmallTicketSolutions

Partners can start a self-service flow or submit data directly to us through a secure API.

  • API-key based JWT authentication
  • Rate limits applied
  • Modern TLS enforced
  • Technical logging for all partner interactions

This ensures partner traffic is controlled, authenticated, and fully auditable.

Just making sure we're on the same page

What we don't do

To keep processes safe and predictable, we are clear about our boundaries:

  • We do not run day-to-day financial administration
  • We do not handle any deductions
  • We are not a replacement for core banking systems
  • We offer rule-based credit underwriting for small programs, not for large bespoke deals
  • We are built for structured, repeatable files, typically up to about one to two million euros when the process is still rules-based. Bespoke committee theatre is a different product.

See how our approach fits your requirements?

If you want a deeper look at our architecture or need support for a risk assessment: