Bancabl Trust Principles

What's true today, and what we're still building.

We would rather tell you plainly what we protect today and what security work is still ahead than describe controls we haven't built yet. This page is our honest account of both.

True today

The principles we already hold ourselves to.

Data minimization

We collect what a feature actually needs to work — not more.

User consent

Entrepreneurs decide what is shared, with whom, and when.

Private relationship notes

Notes and context inside Bancabl Connections stay private by default.

Permission-based institutional access

Institutions see only what an entrepreneur or program has explicitly permitted.

Separation of engagement from underwriting

Social and community engagement on the platform is never treated as a credit decision.

No sale of personal information

We do not sell personal information, and we never will.

No pay-to-play financing

Access to capital pathways is never something an institution or entrepreneur can purchase.

Revocable data access

Entrepreneurs can revoke an institution's access to their information.

Secure system design, as we build

Security is part of how we design each feature as we move toward production, not a step added at the end.

Independent review before scale

We plan independent security and legal reviews before handling sensitive institutional or financial data at scale.

Security roadmap

What isn't built yet — labeled honestly.

None of the items below are operational today. Each is planned for pilot, in development, part of the production security roadmap, or required before institutional deployment.

SOC 2 audit

Not yet underway. Formal audit engagement is required before institutional deployment.

Future capability

SOC 2 auditor engagement

An auditor has not been engaged. This is part of the production security roadmap.

Future capability

Enterprise SSO

SAML / OIDC single sign-on for institutional customers is planned for pilot.

Planned for pilot

Multi-factor authentication

Broader MFA enforcement is planned for pilot rollouts.

Planned for pilot

Tenant isolation controls

Formal, audited tenant-isolation architecture is in development.

Planned for pilot

Audit logging

Structured, exportable audit logging is in development.

Planned for pilot

Data residency commitments

Formal data-residency guarantees are part of the production security roadmap.

Future capability

Encryption architecture

A documented, reviewed encryption architecture is in development.

Planned for pilot

Formal incident-response program

Runbooks, on-call ownership, and notification commitments are required before institutional deployment.

Future capability

Device-management controls

Managed-device and session posture controls are part of the production security roadmap.

Future capability

Procurement-ready security packet

A vendor-risk packet suitable for bank procurement is planned for pilot, once the underlying controls exist.

Planned for pilot

Production-grade institutional controls

Broader institutional-grade controls are required before institutional deployment at scale.

Future capability

Bancabl is not a bank, lender, broker-dealer, or investment adviser. These roadmap items describe security engineering work in progress, not a regulatory certification or approval of any kind.

FAQ

Common questions, answered honestly.

Don't see your question? Email security@bancabl.com.

Questions about how we handle data?

Talk to us directly. We'll tell you what's true today and what's still ahead.