Product integration and security
Integration
Every Credstone product is API-first. You integrate through a versioned API and a set of adapters. The product deploys alongside your core systems and requires no customization of your core to connect.
The integration boundary stops at the API. What happens on your side of that boundary, and what data crosses it, is defined by the adapter contract and is visible to your engineering team before you connect anything to production.
Compliance posture
Every score, flag, and decision our software produces can be traced to the logic and data behind it — no black boxes. Records are tamper-evident and retention-aware from day one, so an audit trail exists before an inspection ever asks for one. Where a product touches a regulated activity, that activity is executed by the licensed institution operating the product, on its own authorizations; see each product's page for its specific vendor-status notice.
Security architecture
Every transmission runs over HTTPS. Stored data sits behind role-based access control, and administrative credentials are segmented. The security programme is led by certified practitioners, and the work happens while we build.
Certification status: ISO 27001 is in progress, led by practitioners who have taken other organisations through it. It stands at implementation, ahead of external audit, and it will be our first certification.
For a deeper technical walkthrough of the integration contract or security architecture for a specific product, talk to our engineering team.