Trust and reliability

SpreadSpace handles lender and borrower financials. Here is how that data is protected, and how reliably the service runs.

Tenant isolation

Every borrower, loan, and document is scoped to your organization. Records from one tenant are never readable from another.

Encryption in transit and at rest

TLS 1.2 or higher on every connection. Databases, document stores, and logs are encrypted at rest with AES-256. Uploaded documents and the production database use dedicated KMS keys that rotate automatically.

Audit trail

PII access, organization activity, and API events are each logged, with up to 7-year retention.

See the log surfaces

Social Security numbers and EINs

Extracted data keeps only the last four digits of a Social Security number or EIN. The full number is masked before the data is stored, and again before it leaves the API. On a borrower profile, those four digits are encrypted a second time.

Data location and deletion

Document data is processed and stored in the United States. Uploaded files are deleted 7 days after upload. Deleting a borrower, loan, or document removes its records and its stored pages.

Backups and recovery

The production database runs across two availability zones and keeps 30 days of point-in-time backups. We rehearse a restore from backup every quarter.

Network protection

The API sits behind a web application firewall and per-client rate limits. The database accepts no connections from the public internet.

Secure development

Every code change is scanned for leaked secrets. The codebase is analyzed for vulnerabilities every day, and its dependencies are checked every week.

API keys and webhooks

API keys are stored only as salted hashes, carry explicit scopes, and can be rotated without downtime. Every webhook delivery is signed.

Read the API security notes

Review our Sub-Processors and Privacy Policy, or talk to us for security documentation.