COMPLIANCE & DUE DILIGENCE

Built for compliance teams to say yes

Your lending team wants to adopt Loan Intel. Before they can, it needs to pass your desk. Here's everything you need to approve it.

Download Compliance Pack

Compliance Walkthrough

Video coming soon

Regulated Data Sources

Every data source on Loan Intel is a public register or regulated provider. No scraped data. No purchased contact lists.

Companies House

Public register of UK companies, charges, officers, and filings

PUBLIC REGISTER

HM Land Registry

Government register of property ownership and title data

GOVERNMENT REGISTER

Experian

FCA-regulated credit reference agency providing company credit reports

FCA REGULATED

ONS

Office for National Statistics — government economic and demographic data

GOVERNMENT DATA

Ring-Fenced Architecture

Each lender operates in a fully isolated environment. Your loan book, payment data, and borrower records sit in a ring-fenced partition that no other user type can access.

Lender

Dedicated tables

Dedicated endpoints

Investment

Dedicated tables

Dedicated endpoints

Solicitor

Dedicated tables

Dedicated endpoints

BLOCKEDNo cross-lender access
BLOCKEDNo cross-role data leakage
BLOCKEDNo API backdoors

Full Audit Trails

Every action is logged. User, timestamp, IP address, endpoint. Your compliance team can review exactly who accessed what, when, and from where.

Audit Log — Real-TimeLive
TimeUserActionIPStatus
14:32:07j.mitchell@lender.co.ukGET /api/portfolio82.132.xxx.xxx200 OK
14:31:52j.mitchell@lender.co.ukPOST /api/screening/run82.132.xxx.xxx201 Created
14:31:44s.clarke@lender.co.ukGET /api/borrower/1234567891.108.xxx.xxx200 OK
14:30:18admin@lender.co.ukPUT /api/settings/retention10.0.xxx.xxx200 OK
14:29:55external@other.co.ukGET /api/portfolio203.45.xxx.xxx403 Forbidden
JWT EnforcementRow-Level IsolationSession ManagementIP Logging

GDPR Compliance

Built in from day one, not bolted on after.

Encryption at Rest

All data encrypted at rest using AES-256 on managed PostgreSQL volumes.

Encryption in Transit

TLS 1.3 enforced on all connections. No plaintext API traffic permitted.

Data Retention Policies

Configurable retention windows. Automated purge on schedule expiry.

Right to Erasure

Full GDPR Article 17 support. One-click data deletion on request.

Content Security Policy

Strict CSP headers block XSS, inline scripts, and unauthorised resources.

httpOnly Cookies

Session tokens stored in httpOnly cookies. No JavaScript access to credentials.

Ready to proceed?

Request a compliance pack, schedule a walkthrough with our team, or start your evaluation today.