Encryption
- At rest: AES-256 on every document, message, and profile field containing PII
- In transit: TLS 1.3 minimum for every request between your browser and the server
- Password storage: bcrypt with per-user salt โ nobody at Credit Quack can see your password, not even the founders
Who can see what
Your assigned team (Lorenzo, Xzavier, plus any credit specialist added to your file) can see your dashboard, documents, and messages. Nobody outside your team โ including other Credit Quack clients โ can see anything about your file.
We never sell, share, or use your data for marketing to third parties. Full policy at /legal/privacy.
First-login password change
Every new account is created with a temporary password (your last name + last 4 of phone) and MUST be changed on first login. The change-password modal cannot be dismissed until a new password is set.
Session security
- Sessions expire after 30 days of inactivity
- Password changes invalidate every existing session
- Suspicious login attempts trigger email alerts