SOC 2 Type 2
An AICPA SOC 2 Type 2 examination covers the design and operating effectiveness of controls over a period, not a point in time — security, availability and confidentiality.
SOC 2 Type 2 certification, a contractual 99.99% availability SLA, managed infrastructure with 24×7 monitoring, and state compliance enforced by the platform rather than by staff training.
An AICPA SOC 2 Type 2 examination covers the design and operating effectiveness of controls over a period, not a point in time — security, availability and confidentiality.
A contractual availability commitment on the hosted platform. A closed store earns nothing, so availability is a commercial term rather than a best effort.
Under the ASP model QFund provides hosting, hardware, system software components, 24×7 support and monitoring, data backups and data archival.
Services →Continuous compliance with U.S. federal and state lending law, maintained as configuration in the platform.
A global delivery model structured to reduce concentration and continuity risk.
Migration and archival handled as controlled processes with documentation, test-and-balance and simulated go-live.
Migration →The weakest control in lending compliance is a person under time pressure at a counter. QFund is designed so the platform is the control.
State rule sets — rate and fee caps, cooling-off periods, concurrent-loan and rollover limits, mandatory state-database queries, disclosure and document requirements, extended payment plans — are configured per state and validated during origination. An offer that would breach them is not generated.
Servicing is the same: fee assessment, notice timing and grace periods follow the state configuration rather than local practice.
QFund provides the platform controls and the configuration to operate compliantly. It does not constitute legal advice, and licensing, policy and regulatory interpretation remain the lender’s responsibility. What the platform guarantees is that the rules you configure are the rules it enforces.
Yes — the SOC 2 Type 2 report is available to prospective and existing clients under NDA. Ask your QFund contact or email our sales team.
QFund held a CMMI DEV/3 appraisal, which has since expired and is no longer claimed. Current independent assurance is SOC 2 Type 2.
Shared, with a clear line. QFund provides the platform controls, the state rule-set configuration and the audit trail. Licensing, lending policy and regulatory interpretation remain yours. The platform’s job is to enforce exactly what you configure, consistently, everywhere.
No. Voice is an input method. Actions run through the same permissions, the same state rule sets and the same audit trail as a click, attributed to the signed-in agent. An agent cannot do by voice anything they could not do by hand.
No, for the same reason. An API call is an input method. Credentials are issued per integration and scoped to a QFund permission set, and every request runs through the same permissions, the same state rule sets and the same audit trail as the equivalent action on screen, attributed to the credential that made it. An integration cannot write a loan a CSR would have been stopped from writing, and platform configuration — loan products, fees, rate tables, state rule sets, users — is not exposed to it at all. API layer →
We answer vendor due-diligence questionnaires as a normal part of the sales process, and the SOC 2 Type 2 report is available under NDA.