Verified Controls for Lending Operations
We advertise only controls that exist in CapGrowth OS today — no bank-grade marketing claims, no unverified certifications, and no encryption-at-rest guarantees we cannot substantiate.
What CapGrowth OS Provides Today
These controls are part of the product and available in verified deployments.
Role-Based Access Control
Company users are assigned roles — owner, manager, loan officer, collections officer, accountant, and viewer — so people only see what their role allows.
Tenant Isolation
Company data is logically isolated. Loan books and financial records are not shared across tenants.
Authentication Basics
Email verification, password reset, and hashed passwords. CSRF protection on forms. Secure cookies in production deployments.
Audit Logs
Operational actions are recorded with user attribution for accountability and review.
Governance Approvals
Sensitive actions can require governance approvals. This is not a custom approval-chain builder.
API Key Authentication
REST API v1 access is authenticated with API keys for integrations.
Upload Access Controls
Document uploads are protected with access controls so files are not freely public.
Exportable Records
Excel and PDF exports support investor and management reporting when you need portable records.
Audit Visibility in the Product
Activity history is a first-class operational screen — not a marketing claim.
Company Users & Roles
Invite staff and assign role-based permissions across the company.
Deployment Considerations
Some protections depend on how CapGrowth OS is hosted. Operators remain responsible for the surrounding infrastructure.
When deployed behind an HTTPS reverse proxy such as Nginx, traffic is encrypted in transit. TLS termination is a deployment choice, not a built-in product claim of always-on encryption everywhere.
Backups are typically handled by the operator or hosting environment. CapGrowth OS does not advertise a product-built platform backups UI.
OS updates, firewalls, and host hardening remain part of normal server operations.
Honesty Over Hype
If a control is not verified in the product, we will not advertise it as available.
Multi-factor authentication is a planned enhancement and is not advertised as available now.
Single sign-on is not advertised as available today.
We do not claim application-managed AES-256 encryption at rest.
This site does not claim SOC 2, PCI, bank certification, or continuous anomaly monitoring as product features.
Scoped Stakeholder Access
Client and investor portals inherit the same access discipline as the admin application.
Scoped Portal Access
Borrowers see their own borrowing activity. Investors see their own accounts and statements.
Authenticated Documents
Portal documents are served through authenticated access, not open public links.
Logged Activity
Meaningful portal and admin actions feed the audit trail for later review.
Your Data Belongs to You
CapGrowth OS does not sell or monetize your lending data. You retain ownership of records on the platform.
Data Export
Export operational and reporting data via Excel/PDF and supported exports. Confirm formats for your deployment.
Account Lifecycle
Data handling at termination follows the retention and deletion policy agreed for your deployment.
Clear Scope
We document what the product controls and what remains an infrastructure responsibility.
Security Questions
How is access controlled?
Company RBAC with roles such as owner, manager, loan officer, collections officer, accountant, and viewer, plus tenant isolation between companies.
Is MFA available today?
No. MFA is a planned enhancement and is not advertised as available now.
Do you claim SOC 2 or bank certification?
No. This site does not claim SOC 2, PCI, or similar certifications.
What security controls exist today?
Password hashing, CSRF protection, secure production cookies, email verification, password reset, RBAC, tenant isolation, upload access control, audit logs, API key authentication, and governance approvals.