Security and compliance

Sensitive borrower data must be handled deliberately.

JengaScore treats documents, CRB data, identity details, and financial statements as high-sensitivity records.

Privacy by design

Controls for borrower documents, CRB data, scores, and lender access

AU

Audit logs

Track scoring runs, approvals, document access, and lender requests.

CO

Borrower consent

Require explicit approval before lender access or report sharing.

EN

Encrypted bundles

Generate password-protected reports and document bundles for approved access.

LS

Least privilege

Separate user-facing flows, scoring services, providers, and secrets.

Data privacy handling

JengaScore separates public matching data from sensitive borrower records.

Lenders see only minimal scored-borrower profiles before borrower approval. Full documents, personal identity data, CRB details, and detailed reports remain restricted until a borrower approves access.

Minimal lender profileScore band, estimated credit range, county, broad evidence categories, loan purpose, and consent status.
Restricted sensitive dataIdentity numbers, phone contacts, raw statements, uploaded documents, CRB records, and detailed score reports.
Purpose limitationBorrower information is processed for scoring, matching, consented lender review, reporting, audit, and compliance.

Encryption strategy

Security controls already applied to data handling design

TR

Transport encryption

Use HTTPS/TLS for web traffic, API traffic, lender access links, and provider integrations.

DB

Database encryption

Encrypt database storage at rest and restrict direct database access by role and environment.

FS

File encryption

Encrypt uploaded documents, converted Markdown, reports, and generated lender bundles at rest.

KE

Key management

Keep encryption keys outside the codebase in environment-specific secret stores with rotation procedures.

RB

Role-based access

Separate borrower, lender, admin, scoring service, worker, and provider permissions.

SH

Secure sharing

Use password-protected encrypted PDFs or archives, expiring access links, and access logs for lender bundles.

Data handler requirements

Compliance controls under Kenya’s data protection framework.

Collad and participating processors maintain documented compliance evidence and data-handler credentials where applicable.

ODPC registration certificateData Controller and Data Processor registration evidence is retained where applicable and available for audit.
Data Protection Impact AssessmentThe DPIA record covers high-risk processing such as credit profiling, CRB use, AI-assisted analysis, and document sharing.
Processor agreementsData processing agreements govern CRB, AI, payment, hosting, email, storage, and lender-access service providers.
Data protection officer or leadA responsible data protection lead owns data subject rights, breach handling, retention, access reviews, and ODPC correspondence.
Handler certificates registerThe handler register records internal and external data handlers, ODPC status, role, scope, access level, and training evidence.
AI Help
Collad AI Assistant Online

Hello. I can help with borrower profiles, document readiness, scoring steps, lender matching, and support routing.

I need help getting started.

Create a borrower profile, add your identity and consent details, then upload your financial or asset documents.