Trust Center
Security and trust, by design.
CreditGPT analyzes some of the most sensitive client documents. Protecting that data — with enterprise-grade encryption, strict access controls, and full transparency — is foundational to everything we build.
Resources
Security and Compliance Overview
SOC 2 Auditor Engagement Letter
Penetration Test Summary (May 2026)
AI & Data Use Summary
Subprocessor Summary
Data Flow & Security Controls
AWS Setup, Tenant Separation, and Data Protection Summary
Monitoring
Continuously monitored by Secureframe
FAQs
What customer data does CreditGPT process?
CreditGPT processes customer-provided credit documents and related data necessary to provide the service. This may include uploaded documents, document metadata, user and tenant account data, prompts or workflow instructions, derived outputs, citations, workflow metadata, and operational logs. CreditGPT’s system architecture includes document storage, parsing, retrieval of relevant document sections, LLM-assisted analysis, and generation of structured outputs.
Where is customer data stored and processed?
Customer documents are stored in AWS S3, while document metadata, derived outputs, user records, and tenant records are stored in MongoDB Atlas. CreditGPT also uses service providers for application hosting, workflow orchestration, document parsing, observability, identity/SSO, LLM inference, source control, and CI/CD. A current subprocessor summary is available under NDA.
How does CreditGPT isolate customer data?
CreditGPT enforces tenant isolation at both the application layer and the AWS policy layer. Production S3 objects are stored under tenant-scoped prefixes, and S3 access uses short-lived STS credentials scoped to the authenticated tenant’s S3 prefix. CreditGPT also validates that each object key matches the authenticated tenant before any S3 operation or presigned URL is generated.
How is customer data encrypted?
CreditGPT protects data in transit using HTTPS/TLS. For AWS S3 document storage, buckets enforce TLS-only transport and SSE-KMS encryption at rest using environment-specific KMS keys. Production, Development, and Demo environments use separate AWS resources, including separate S3 buckets, KMS keys, IAM roles, and bootstrap IAM users.
Does CreditGPT use customer data to train AI models?
No. CreditGPT does not train models on customer data. CreditGPT uses LLM providers as processing components within the customer’s document-analysis workflow.
Does CreditGPT have Zero Data Retention agreements?
Yes, we have Zero Data Retention ("ZDR") Agreements in place with all of our LLM providers.
How does CreditGPT handle security incidents?
CreditGPT maintains a documented Security Incident Response Plan covering detection, reporting, verification, assessment, containment, mitigation, post-breach response, documentation, and post-incident review. Suspected incidents are escalated to the Security Response Team and documented in an incident log and/or corrective action plan.
What is CreditGPT’s backup and recovery posture?
CreditGPT maintains a Business Continuity and Disaster Recovery Plan. Database backups must be performed, retained for at least 30 days, and periodically tested. Current engineering recovery objectives are a 24-hour Recovery Time Objective and a 24-hour Recovery Point Objective.
Does CreditGPT perform penetration testing and vulnerability management?
CreditGPT maintains a vulnerability and patch management process that prioritizes remediation based on severity and risk. CreditGPT’s security program includes third-party penetration testing and/or internal security assessments at least annually. A customer-safe penetration test executive summary and remediation status may be made available under NDA, where applicable.