Security

Verified Controls for Lending Operations

We advertise only controls that exist in CapGrowth OS today — no bank-grade marketing claims, no unverified certifications, and no encryption-at-rest guarantees we cannot substantiate.

Reference Enterprise — illustrative product screens · no production customer data
Application Controls

What CapGrowth OS Provides Today

These controls are part of the product and available in verified deployments.

Role-Based Access Control

Company users are assigned roles — owner, manager, loan officer, collections officer, accountant, and viewer — so people only see what their role allows.

Tenant Isolation

Company data is logically isolated. Loan books and financial records are not shared across tenants.

Authentication Basics

Email verification, password reset, and hashed passwords. CSRF protection on forms. Secure cookies in production deployments.

Audit Logs

Operational actions are recorded with user attribution for accountability and review.

Governance Approvals

Sensitive actions can require governance approvals. This is not a custom approval-chain builder.

API Key Authentication

REST API v1 access is authenticated with API keys for integrations.

Upload Access Controls

Document uploads are protected with access controls so files are not freely public.

Exportable Records

Excel and PDF exports support investor and management reporting when you need portable records.

Evidence

Audit Visibility in the Product

Activity history is a first-class operational screen — not a marketing claim.

Screen 18 Governance

Audit Logs

Operational audit trail of platform actions for accountability.

On product tour
Screen 23 Administration

Company Users & Roles

Invite staff and assign role-based permissions across the company.

On product tour
Infrastructure

Deployment Considerations

Some protections depend on how CapGrowth OS is hosted. Operators remain responsible for the surrounding infrastructure.

TLS in transit

When deployed behind an HTTPS reverse proxy such as Nginx, traffic is encrypted in transit. TLS termination is a deployment choice, not a built-in product claim of always-on encryption everywhere.

Server & database backups

Backups are typically handled by the operator or hosting environment. CapGrowth OS does not advertise a product-built platform backups UI.

Patching & hardening

OS updates, firewalls, and host hardening remain part of normal server operations.

What We Do Not Claim

Honesty Over Hype

If a control is not verified in the product, we will not advertise it as available.

No MFA available today

Multi-factor authentication is a planned enhancement and is not advertised as available now.

No SSO product claim

Single sign-on is not advertised as available today.

No AES-at-rest product claim

We do not claim application-managed AES-256 encryption at rest.

No SOC 2 / PCI claims

This site does not claim SOC 2, PCI, bank certification, or continuous anomaly monitoring as product features.

Portal Access

Scoped Stakeholder Access

Client and investor portals inherit the same access discipline as the admin application.

Scoped Portal Access

Borrowers see their own borrowing activity. Investors see their own accounts and statements.

Authenticated Documents

Portal documents are served through authenticated access, not open public links.

Logged Activity

Meaningful portal and admin actions feed the audit trail for later review.

Privacy

Your Data Belongs to You

CapGrowth OS does not sell or monetize your lending data. You retain ownership of records on the platform.

Data Export

Export operational and reporting data via Excel/PDF and supported exports. Confirm formats for your deployment.

Account Lifecycle

Data handling at termination follows the retention and deletion policy agreed for your deployment.

Clear Scope

We document what the product controls and what remains an infrastructure responsibility.

FAQ

Security Questions

How is access controlled?

Company RBAC with roles such as owner, manager, loan officer, collections officer, accountant, and viewer, plus tenant isolation between companies.

Is MFA available today?

No. MFA is a planned enhancement and is not advertised as available now.

Do you claim SOC 2 or bank certification?

No. This site does not claim SOC 2, PCI, or similar certifications.

What security controls exist today?

Password hashing, CSRF protection, secure production cookies, email verification, password reset, RBAC, tenant isolation, upload access control, audit logs, API key authentication, and governance approvals.

Questions About Security?

Ask us about RBAC, audit logs, tenant isolation, API keys, and how TLS is configured in your deployment environment. Sign in at app.capgrowthos.com if you already have access.