Standard readiness and account information
✓
Account and organization informationName, email address, organization affiliation, role, and other information needed to operate an approved account.
✓
Participant-provided readiness informationBusiness profile, goals, readiness activities, narratives, financial summaries, and other information entered by the participant.
Participant-provided sensitive documents
When an organization enables a document workflow, a participant may be asked to upload documents such as tax returns, W-2s, 1099s, or financial statements. Those documents may contain identifiers or financial information that Groundwork. does not request as standard readiness fields. Groundwork. may use authorized service providers to store documents, deliver transactional communications, and perform AI-assisted extraction for the enabled workflow. Documents and extracted information are handled according to the applicable permissions, participant disclosures, and approved use.
Information Groundwork. does not request as standard readiness fields
- Social Security numbers or full Tax Identification Numbers
- Full credit reports or credit scores; participants may provide a general credit range
- Online banking usernames, passwords, or financial account login credentials
- Payment card numbers for readiness participation
✓
Organization-led participationAccounts and organizational workflows are established through an approved partnership and invitation process rather than public self-service access.
✓
Permission-based visibilityWhat an organization can see depends on organization membership, assigned roles, accepted relationships, enabled workflows, and the approved scope of participation.
✓
Participant consentInformation is made available through the applicable relationship and consent flow. A lender does not receive unrestricted access to a participant's complete Groundwork. account.
✓
Participant ownershipParticipants retain ownership of the content they submit. Groundwork. receives the limited rights needed to operate the service and handle information as described in the Terms and Privacy Policy.
✓
HTTPS/TLS EncryptionPlatform traffic is protected in transit using HTTPS/TLS.
✓
Secure AuthenticationPasswords are hashed using bcrypt. Groundwork. sign-in flows use session-based authentication, HTTP-only cookies, and email one-time passcode verification after password authentication.
✓
Organization and role boundariesOrganization context and assigned roles are used to limit access. Visibility is further governed by accepted relationships, enabled workflows, permissions, and participant consent.
✓
No Data SellingGroundwork. does not sell or monetize borrower or institution data. Any sharing is handled through the applicable workflow and disclosures.
✓
Deletion requestsBorrowers may request deletion through the platform or by contacting us. Groundwork. processes requests according to its applicable data-handling procedures.
✓
Encrypted at RestPostgreSQL database encrypted at rest on Railway's managed infrastructure.
✓
Managed InfrastructureGroundwork. uses managed hosting and database infrastructure. Service-provider controls support Groundwork's security program but do not independently certify Groundwork's compliance.
✓
Transactional communicationsGroundwork. uses an authorized email service provider for account verification, invitations, and operational notifications.
✓
Enabled document workflowsWhen enabled for an organization, participants may upload requested documents. Authorized service providers may support storage and AI-assisted extraction. Access and use remain limited by the applicable workflow, permissions, disclosures, and approved purpose.
GLBA
Groundwork. provides information about its data practices and security controls to support partner review. Each institution determines how GLBA and its vendor-oversight requirements apply to the relationship.
Shared Responsibility
Privacy Rights
Groundwork. responds to applicable requests concerning access, correction, deletion, and sale or sharing. Available rights and exceptions depend on the governing law and circumstances.
As Applicable
NY SHIELD Act
Groundwork. evaluates safeguards for information handled by the platform. Applicability and compliance depend on the information, business scope, and complete administrative, technical, and physical security program.
Control Alignment
Institutional Due Diligence
Groundwork. can provide information to support a credit union's or lender's vendor review. Approval and ongoing oversight remain with the institution under its own policies and applicable guidance.
Partner-Led Review
Fair Lending
Groundwork. organizes readiness information and does not approve, deny, price, or recommend credit. Lenders retain responsibility for underwriting, credit decisions, fair-lending compliance, and their use of participant information.
No Credit Decisions
BSA / AML
Groundwork. does not originate loans, move funds, hold member funds, or perform an institution's identity-verification or transaction-monitoring duties. Each institution determines and fulfills its applicable BSA/AML obligations.
Institution Responsibility
06 · Review
Institutional Due Diligence Materials
Groundwork. can discuss security, privacy, implementation, and contractual documentation during a prospective partner's due diligence process. Materials are provided as applicable to the proposed relationship and approved scope.
MSA
Operations Agreement
Master services agreement covering scope, responsibilities, data ownership, and termination rights.
Request document →
SEC
Security Overview
Technical security controls, encryption standards, access controls, and incident response procedures.
Request document →
PRI
Privacy Policy
Public information about data collection, use, visibility, participant choices, and Groundwork's privacy practices.
View Privacy Policy →
BCP
Business Continuity Plan
Disaster recovery procedures, data backup policies, and service restoration commitments.
Request document →
SOW
Implementation SOW
Statement of work covering onboarding, deliverables, timeline, and acceptance criteria.
Request document →
SLA
Service Level Agreement
Uptime commitments, support response times, and performance standards under the applicable partnership agreement.
Request document →