How SourceUSA Protects Financing Information
Private Document Storage
Financing documents are stored outside the publicly addressable web directory. Vault files are encrypted before storage using authenticated AES-256-GCM encryption. A database record stores authorization and audit metadata separately from the encrypted file.
No Sensitive Email Attachments
Lender notification emails contain opportunity information and authenticated links—not financial statements, tax documents or other sensitive vault files.
You Decide Who Gets Document Access
A lender being matched to a financing request does not automatically give that lender access to your vault. Document authorization is a separate applicant-controlled action and can have an expiration or be revoked.
Auditing and Malware Controls
Document uploads, authorizations, revocations and authenticated lender views/downloads are recorded. The production deployment must connect the included malware-scanning hook to an approved scanning service before files are made available to lenders.
Production Security Requirements
HTTPS/TLS, strong server configuration, protected encryption keys, database backups, MFA, monitoring, vulnerability patching, rate limiting, secure session cookies and independent security testing are deployment requirements—not optional marketing features.