Audit logs
Track scoring runs, approvals, document access, and lender requests.
Security and compliance
JengaScore treats documents, CRB data, identity details, and financial statements as high-sensitivity records.
Privacy by design
Track scoring runs, approvals, document access, and lender requests.
Require explicit approval before lender access or report sharing.
Generate password-protected reports and document bundles for approved access.
Separate user-facing flows, scoring services, providers, and secrets.
Data privacy handling
Lenders see only minimal scored-borrower profiles before borrower approval. Full documents, personal identity data, CRB details, and detailed reports remain restricted until a borrower approves access.
Encryption strategy
Use HTTPS/TLS for web traffic, API traffic, lender access links, and provider integrations.
Encrypt database storage at rest and restrict direct database access by role and environment.
Encrypt uploaded documents, converted Markdown, reports, and generated lender bundles at rest.
Keep encryption keys outside the codebase in environment-specific secret stores with rotation procedures.
Separate borrower, lender, admin, scoring service, worker, and provider permissions.
Use password-protected encrypted PDFs or archives, expiring access links, and access logs for lender bundles.
Data handler requirements
Collad and participating processors maintain documented compliance evidence and data-handler credentials where applicable.