Skip to main content

Security

Credit agreements and borrower financials are among the most sensitive documents a firm holds. We employ state-of-the-art security measures and undergo regular security reviews from third-party security firms to ensure the highest level of data protection.

Cyber Essentials Certified

ExactCov security practices and controls have been independently audited by experts.

Encryption

Data is encrypted in transit and at rest using the most secure algorithms available.

Zero Data Retention

Your data is never used to train AI models and is deleted permanently once you remove it.

Two Factor Authentication

All internal accounts require two-factor authentication to mitigate the risk of unauthorised access.

Zero-Trust Architecture

ExactCov was architected from the beginning with security in mind. We employ a zero-trust security model, which means that no components or systems can communicate with each other without specific authorisation and authentication.

Self-Hosted and Tokenised Data Options

ExactCov can be configured with a self-hosted or third-party data storage layer so that files never touch ExactCov servers or infrastructure. You and your borrowers interact with ExactCov directly, but the files are stored on independent infrastructure, much like an e-commerce site uses a third-party payment processor like Stripe for credit cards.

Principle of Least Privilege

Only strictly required access is granted to accounts and personnel to minimise risk.

Automated Security Checks

All code, libraries and operating systems are regularly scanned for vulnerabilities and patches or updates are made to mitigate identified security issues.

Continuous Security Monitoring & Threat Detection

We leverage modern AI tools and run continuous monitoring on our infrastructure. Threat detection monitors for malicious activity and anomalous behaviour to keep systems and data secure.

Secure Links for Borrower Access

ExactCov leverages secure links for borrower authentication when collecting financials and certificates. This is more convenient for borrowers and more secure, because departed borrower contacts lose access the moment their e-mail is shut off.

Account Level Security

All accounts must meet minimum requirements for password complexity. Account sessions are protected through inactivity timeouts.

Regular Access Reviews

Access to systems and accounts is regularly reviewed to ensure no personnel have inappropriate access to systems or data.

Ready to retire the covenant spreadsheet?

Learn how AI-powered covenant monitoring catches breaches early and saves days every test period.