SECURITY & PRIVACY

How SourceUSA Protects Financing Information

Important: Because SourceUSA is a web platform, information necessarily travels between your browser and SourceUSA's servers. In production this transmission must use HTTPS/TLS encryption. SourceUSA does not represent that data literally never traverses the internet.

Private Document Storage

Financing documents are stored outside the publicly addressable web directory. Vault files are encrypted before storage using authenticated AES-256-GCM encryption. A database record stores authorization and audit metadata separately from the encrypted file.

No Sensitive Email Attachments

Lender notification emails contain opportunity information and authenticated links—not financial statements, tax documents or other sensitive vault files.

You Decide Who Gets Document Access

A lender being matched to a financing request does not automatically give that lender access to your vault. Document authorization is a separate applicant-controlled action and can have an expiration or be revoked.

Auditing and Malware Controls

Document uploads, authorizations, revocations and authenticated lender views/downloads are recorded. The production deployment must connect the included malware-scanning hook to an approved scanning service before files are made available to lenders.

Production Security Requirements

HTTPS/TLS, strong server configuration, protected encryption keys, database backups, MFA, monitoring, vulnerability patching, rate limiting, secure session cookies and independent security testing are deployment requirements—not optional marketing features.