COMPLIANCE & DUE DILIGENCE
Built for compliance teams to say yes
Your lending team wants to adopt Loan Intel. Before they can, it needs to pass your desk. Here's everything you need to approve it.
Regulated Data Sources
Every data source on Loan Intel is a public register or regulated provider. No scraped data. No purchased contact lists.
Companies House
Public register of UK companies, charges, officers, and filings
HM Land Registry
Government register of property ownership and title data
Experian
FCA-regulated credit reference agency providing company credit reports
ONS
Office for National Statistics — government economic and demographic data
Ring-Fenced Architecture
Each lender operates in a fully isolated environment. Your loan book, payment data, and borrower records sit in a ring-fenced partition that no other user type can access.
Lender
Dedicated tables
Dedicated endpoints
Investment
Dedicated tables
Dedicated endpoints
Solicitor
Dedicated tables
Dedicated endpoints
Full Audit Trails
Every action is logged. User, timestamp, IP address, endpoint. Your compliance team can review exactly who accessed what, when, and from where.
| Time | User | Action | IP | Status |
|---|---|---|---|---|
| 14:32:07 | j.mitchell@lender.co.uk | GET /api/portfolio | 82.132.xxx.xxx | 200 OK |
| 14:31:52 | j.mitchell@lender.co.uk | POST /api/screening/run | 82.132.xxx.xxx | 201 Created |
| 14:31:44 | s.clarke@lender.co.uk | GET /api/borrower/12345678 | 91.108.xxx.xxx | 200 OK |
| 14:30:18 | admin@lender.co.uk | PUT /api/settings/retention | 10.0.xxx.xxx | 200 OK |
| 14:29:55 | external@other.co.uk | GET /api/portfolio | 203.45.xxx.xxx | 403 Forbidden |
GDPR Compliance
Built in from day one, not bolted on after.
Encryption at Rest
All data encrypted at rest using AES-256 on managed PostgreSQL volumes.
Encryption in Transit
TLS 1.3 enforced on all connections. No plaintext API traffic permitted.
Data Retention Policies
Configurable retention windows. Automated purge on schedule expiry.
Right to Erasure
Full GDPR Article 17 support. One-click data deletion on request.
Content Security Policy
Strict CSP headers block XSS, inline scripts, and unauthorised resources.
httpOnly Cookies
Session tokens stored in httpOnly cookies. No JavaScript access to credentials.
Ready to proceed?
Request a compliance pack, schedule a walkthrough with our team, or start your evaluation today.