Security

Every check Iridium runs, every debtor it contacts and every decision it clears stays attached to the invoice, timestamped and attributed. When your bank, your auditor or your credit committee asks how you knew a funded invoice was real, the answer is already there. The data behind it stays protected and in the United States.

Request security documentation

Request access through our Trust Center.

Data protection

01

Residency

Your data stays on AWS in the United States. Encrypted in transit and at rest, with keys managed in AWS KMS, and client data segregated per tenant.

02

Access

Only the people supporting your account can reach it. Production access is role-based and every session is logged. Your team signs in with SSO.

03

Model training

No AI provider we use may train on your data. Your data runs your service. Where we improve the platform, we use only data that has been de-identified so it no longer identifies you or anyone else.

Human oversight

Iridium operates inside rules you set, and its actions are logged the same way human actions are. Any check that fails stops and waits for a person.

  1. 01

    Check

    The invoice is checked against its source documents.

  2. 02

    Exception

    A failed check waits for a person.

  3. 03

    Review

    Your team applies the rules you set.

  4. 04

    Record

    The decision stays timestamped and attributed.

Illustrative exception review

What the log holds

Extractions, checks, debtor contacts, and decisions are each timestamped and attributed, so you can hand the record to whoever needs to see it. It's written for the questions banks ask.

Compliance

Iridium's controls are independently examined (SOC 2 Type I, Security criteria), with continuous control monitoring in place. We carry cyber liability and technology E&O insurance, with umbrella coverage on top. Certificates are available on request.

Reports, the subprocessor list and our security documentation live in the Trust Center, with the detail available under NDA.

Visit the Trust Center

Diligence

01Where is my data hosted?

On AWS, in the United States. Client data is segregated per tenant and encrypted in transit and at rest.

02Is my portfolio data shared with other factors?

Not in any form that identifies you. Your client and debtor data runs your operation, and platform improvements use only de-identified data. Cross-customer fraud matching is opt-in. If you join, invoice and debtor identifiers are matched against other participating lenders, and your identity and terms are never revealed without your consent on each match.

03Can you pass our bank's vendor review?

Yes. Iridium Controls are independently examined (SOC 2 Type I, Security criteria), documentation is available under NDA in our Trust Center, and our team has filled in these questionnaires before. We're ready for yours.

Reporting a vulnerability.

Send security issues to security@iridiumcredit.com. We read every report.