Creditlinker

Your data belongs
to you. Full stop.

Your Financial Passport belongs to you. No one can access it unless you give permission, and you can withdraw that permission at any time.

Security by design.

Security isn't just about keeping data private. It's about making sure every Financial Passport can be trusted.

Creditlinker is designed so that trust doesn't depend on people. Sensitive actions require authorization, records cannot be silently changed, and every important operation leaves an auditable history.

Access Security

Who can access your Financial Passport.

  • Consent-based access. No financial institution can view your Financial Passport without your approval.
  • Role-based access control (RBAC). Businesses, financial institutions, and developers operate in separate environments.
  • Time-limited access. Every grant has an expiry and can only be extended with your approval.
  • Revocation. Access can be withdrawn at any time, effective immediately.
  • Authentication. User accounts are protected using secure authentication and session management.
  • Multi-factor authentication. Available for institutional and admin accounts.

Data Security

How the data is protected.

  • Encryption. TLS 1.3 in transit, AES-256 at rest.
  • Secrets management. Credentials and keys are held in dedicated secrets infrastructure, never in code or logs.
  • Secure storage. Data is held in access-controlled, isolated storage environments.
  • Backups. Records are backed up on a regular schedule to prevent data loss.
  • Infrastructure isolation. Business data is processed in isolated environments to reduce security risk.

Record Integrity

How you know the data wasn't changed.

  • Tamper-evident records. Every Financial Passport is sealed with cryptographic proofs that make unauthorized changes immediately detectable.
  • Append-only history. Records are never silently overwritten. Every change is versioned.
  • Independent verification. Institutions can verify the integrity of a Financial Passport without relying on Creditlinker's word.

Accountability

How you know what happened.

  • Audit logging. Every data update, consent approval, and access request is recorded with a timestamp.
  • Version history. Every change to a Financial Passport is preserved, not replaced.
  • Access records. A full record of who accessed what, and when.
  • Security disclosure. Found a vulnerability? Report it to security@creditlinker.com and we'll respond within 48 hours.

Cryptographic integrity.

Every Financial Passport is protected using cryptographic proofs that make unauthorized changes immediately detectable. At the end of every business day, Creditlinker creates a cryptographic proof of that day's records and permanently seals it. If any record is changed later, the system can identify exactly where the change occurred and the proof will no longer match. Institutions don't have to rely on Creditlinker's word. They can verify the integrity of a Financial Passport independently.

Build your financial identity

Found a vulnerability? security@creditlinker.com or review our Privacy Policy.