Security
Definite sits next to systems of record at regulated institutions. This page describes how the service is built to limit what it can reach and to make its own behaviour auditable.
Read-only by design
The strongest control we have is the one we do not need to enforce at runtime: Definite is never granted write capability.
- Granted: read access to the extracts and feeds you connect.
- Never granted: write access to a core, ledger, or loan system, and payment initiation of any kind.
- Every action taken against your systems is logged and available to you as an activity record.
Data in transit and at rest
- Connections use key-based SFTP, an authenticated file drop, or a read-scoped API.
- Traffic is encrypted in transit. Stored data and snapshots are encrypted at rest.
- Every snapshot is hashed on arrival, before any check runs, so results always trace to an exact copy of what was received.
Failing closed
When a feed is missing, late, or incomplete, the affected checks return Cannot verify and the dependent filing lines are held back. The service will not infer, estimate, or substitute a figure in order to produce a clean result.
Evidence and auditability
- Every verdict records the inputs, the rule version applied, the result, and the time it ran.
- Each record is linked to the one before it, so an alteration after the fact is detectable.
- Evidence packages can be exported and verified independently, without trusting Definite.
Access control
- Access to production is limited to staff who need it, and is reviewed.
- Administrative access requires multi-factor authentication.
- Customer data access is logged.
Subprocessors and hosting
We use a small number of infrastructure and support vendors, each bound by contract to protect the data they handle. A current list is available to customers on request.
Assurance
We can share our current security posture, architecture detail, and the results of any third-party assessment under NDA. If your procurement process requires a specific questionnaire or framework, tell us and we will work through it.
Reporting a vulnerability
If you believe you have found a security issue, email mazin@usedefinite.com with enough detail to reproduce it. We will acknowledge, investigate, and keep you updated. Please do not publicly disclose until we have had a chance to fix it.