What's true today, and what we're still building.
We would rather tell you plainly what we protect today and what security work is still ahead than describe controls we haven't built yet. This page is our honest account of both.
True today
The principles we already hold ourselves to.
Data minimization
We collect what a feature actually needs to work — not more.
User consent
Entrepreneurs decide what is shared, with whom, and when.
Private relationship notes
Notes and context inside Bancabl Connections stay private by default.
Permission-based institutional access
Institutions see only what an entrepreneur or program has explicitly permitted.
Separation of engagement from underwriting
Social and community engagement on the platform is never treated as a credit decision.
No sale of personal information
We do not sell personal information, and we never will.
No pay-to-play financing
Access to capital pathways is never something an institution or entrepreneur can purchase.
Revocable data access
Entrepreneurs can revoke an institution's access to their information.
Secure system design, as we build
Security is part of how we design each feature as we move toward production, not a step added at the end.
Independent review before scale
We plan independent security and legal reviews before handling sensitive institutional or financial data at scale.
Security roadmap
What isn't built yet — labeled honestly.
None of the items below are operational today. Each is planned for pilot, in development, part of the production security roadmap, or required before institutional deployment.
SOC 2 audit
Not yet underway. Formal audit engagement is required before institutional deployment.
SOC 2 auditor engagement
An auditor has not been engaged. This is part of the production security roadmap.
Enterprise SSO
SAML / OIDC single sign-on for institutional customers is planned for pilot.
Multi-factor authentication
Broader MFA enforcement is planned for pilot rollouts.
Tenant isolation controls
Formal, audited tenant-isolation architecture is in development.
Audit logging
Structured, exportable audit logging is in development.
Data residency commitments
Formal data-residency guarantees are part of the production security roadmap.
Encryption architecture
A documented, reviewed encryption architecture is in development.
Formal incident-response program
Runbooks, on-call ownership, and notification commitments are required before institutional deployment.
Device-management controls
Managed-device and session posture controls are part of the production security roadmap.
Procurement-ready security packet
A vendor-risk packet suitable for bank procurement is planned for pilot, once the underlying controls exist.
Production-grade institutional controls
Broader institutional-grade controls are required before institutional deployment at scale.
Bancabl is not a bank, lender, broker-dealer, or investment adviser. These roadmap items describe security engineering work in progress, not a regulatory certification or approval of any kind.
