Security & compliance

Security, availability and compliance you can hand to an examiner

SOC 2 Type 2 certification, a contractual 99.99% availability SLA, managed infrastructure with 24×7 monitoring, and state compliance enforced by the platform rather than by staff training.

SOC 2Type 2 — AICPA assured controls
99.99%availability SLA
24×7support and monitoring
Assurance

What is independently verified

SOC 2 Type 2

An AICPA SOC 2 Type 2 examination covers the design and operating effectiveness of controls over a period, not a point in time — security, availability and confidentiality.

99.99% availability SLA

A contractual availability commitment on the hosted platform. A closed store earns nothing, so availability is a commercial term rather than a best effort.

Managed infrastructure

Under the ASP model QFund provides hosting, hardware, system software components, 24×7 support and monitoring, data backups and data archival.

Services

Regulatory compliance

Continuous compliance with U.S. federal and state lending law, maintained as configuration in the platform.

Low-risk delivery model

A global delivery model structured to reduce concentration and continuity risk.

Data services discipline

Migration and archival handled as controlled processes with documentation, test-and-balance and simulated go-live.

Migration
Compliance in the platform

Rules that are enforced, not remembered

The weakest control in lending compliance is a person under time pressure at a counter. QFund is designed so the platform is the control.

State rule sets — rate and fee caps, cooling-off periods, concurrent-loan and rollover limits, mandatory state-database queries, disclosure and document requirements, extended payment plans — are configured per state and validated during origination. An offer that would breach them is not generated.

Servicing is the same: fee assessment, notice timing and grace periods follow the state configuration rather than local practice.

Audit position

  • Every transaction attributed to a user and timestamped
  • Reversals only through time-bound rollback and void, recorded
  • Accounting entries generated from the same events, not re-keyed
  • Decision reason codes retained on declines and manual reviews
  • Notices and disclosures stored against the loan file
  • Voice-assisted actions audited identically to manual ones

One important boundary

QFund provides the platform controls and the configuration to operate compliantly. It does not constitute legal advice, and licensing, policy and regulatory interpretation remain the lender’s responsibility. What the platform guarantees is that the rules you configure are the rules it enforces.

Availability

What the SLA covers

Availability target
99.99% on the hosted (ASP) platform.
Monitoring
24×7 support and monitoring of the hosted environment.
Backups
Managed data backups, with data archival as a standard ASP service.
Patching & upgrades
Technical upgrades and functionality upgrades included in the ASP engagement.
System components
JBoss application server, Oracle database and Linux, managed by QFund.
Deployment alternative
Licensed deployment on customer infrastructure, where the customer assumes infrastructure operations.
FAQ

Security questions

Can we see the SOC 2 report?

Yes — the SOC 2 Type 2 report is available to prospective and existing clients under NDA. Ask your QFund contact or email our sales team.

Did QFund previously hold a CMMI appraisal?

QFund held a CMMI DEV/3 appraisal, which has since expired and is no longer claimed. Current independent assurance is SOC 2 Type 2.

Who is responsible for compliance — you or us?

Shared, with a clear line. QFund provides the platform controls, the state rule-set configuration and the audit trail. Licensing, lending policy and regulatory interpretation remain yours. The platform’s job is to enforce exactly what you configure, consistently, everywhere.

Does the AI assistant weaken the control environment?

No. Voice is an input method. Actions run through the same permissions, the same state rule sets and the same audit trail as a click, attributed to the signed-in agent. An agent cannot do by voice anything they could not do by hand.

What about the APIs — does opening the platform up weaken that?

No, for the same reason. An API call is an input method. Credentials are issued per integration and scoped to a QFund permission set, and every request runs through the same permissions, the same state rule sets and the same audit trail as the equivalent action on screen, attributed to the credential that made it. An integration cannot write a loan a CSR would have been stopped from writing, and platform configuration — loan products, fees, rate tables, state rule sets, users — is not exposed to it at all. API layer →

Send us your security questionnaire

We answer vendor due-diligence questionnaires as a normal part of the sales process, and the SOC 2 Type 2 report is available under NDA.