trust & security

the controls are part of the product.

KredFlow is being designed as a lender-supervised technology layer: minimal data, auditable decisions, direct fund flows and clear borrower communications.

platform control framework

control

lender authority

The regulated lender approves the programme, sets credit policy, makes final decisions and issues loan documents.

control

data minimisation

KredFlow will retain only the information needed for its contracted role. Raw bureau and bank data should remain in lender-approved systems where possible.

control

explicit consent

Each data request must state its purpose, recipient and duration. Refusing optional data will not be disguised as a technical failure.

control

India-first storage

Borrower data architecture will be approved for India-based storage before launch. Current public website data is limited to standard hosting logs and emails users choose to send.

control

role-based access

Operations access will be limited by job need, protected with strong authentication and recorded in audit logs.

control

no pass-through funds

KredFlow will not receive loan disbursals or borrower repayments into its own bank account.

control

explainable outcomes

Decision inputs, policy version and reason codes will be recorded so the lender can review how a case was handled.

control

incident readiness

Security events will follow a documented response, escalation and legally required notification process.

control

vendor isolation

A software vendor receives transaction status needed to complete the sale—not the buyer's sensitive underwriting file.

data journey

collect less. separate responsibilities.

  1. explain

    Show what information is needed before requesting it.

  2. consent

    Capture a clear, time-stamped and purpose-specific choice.

  3. verify

    Use lender-approved sources for business identity, KYC, AML and credit assessment.

  4. limit

    Expose only the minimum fields each vendor, operator or service provider needs.

  5. retain responsibly

    Follow the lender-approved retention schedule and delete or de-identify when no longer required.

important distinction

design intent is not a certification.

This page describes KredFlow's control model. It does not claim ISO, SOC, PCI, RBI authorisation or a completed lender audit. Verified certifications and the appointed lender will be published only when they exist.