Institutional security and privacy

Security, Privacy & Institutional Trust

Groundwork. supports organization-led, invitation-based participation. Security controls, permissions, and consent-aware visibility help partners manage readiness relationships within an approved scope.

Organization-Led Access
Role-Based Permissions
Consent-Aware Visibility
HTTPS/TLS in Transit
Due Diligence Support
01 · Data
Information handled by Groundwork.
The information involved depends on the partner relationship, participant activity, and workflows enabled for the organization.
Standard readiness and account information
Account and organization informationName, email address, organization affiliation, role, and other information needed to operate an approved account.
Participant-provided readiness informationBusiness profile, goals, readiness activities, narratives, financial summaries, and other information entered by the participant.
Participant-provided sensitive documents
When an organization enables a document workflow, a participant may be asked to upload documents such as tax returns, W-2s, 1099s, or financial statements. Those documents may contain identifiers or financial information that Groundwork. does not request as standard readiness fields. Groundwork. may use authorized service providers to store documents, deliver transactional communications, and perform AI-assisted extraction for the enabled workflow. Documents and extracted information are handled according to the applicable permissions, participant disclosures, and approved use.
Information Groundwork. does not request as standard readiness fields
  • Social Security numbers or full Tax Identification Numbers
  • Full credit reports or credit scores; participants may provide a general credit range
  • Online banking usernames, passwords, or financial account login credentials
  • Payment card numbers for readiness participation
02 · Model
Access, consent, and data ownership
Participation and organizational visibility are governed by relationships, permissions, and enabled workflows.
Organization-led participationAccounts and organizational workflows are established through an approved partnership and invitation process rather than public self-service access.
Permission-based visibilityWhat an organization can see depends on organization membership, assigned roles, accepted relationships, enabled workflows, and the approved scope of participation.
Participant consentInformation is made available through the applicable relationship and consent flow. A lender does not receive unrestricted access to a participant's complete Groundwork. account.
Participant ownershipParticipants retain ownership of the content they submit. Groundwork. receives the limited rights needed to operate the service and handle information as described in the Terms and Privacy Policy.
03 · Controls
Implemented platform controls
Current technical and operational controls used to support the Groundwork. platform.
HTTPS/TLS EncryptionPlatform traffic is protected in transit using HTTPS/TLS.
Secure AuthenticationPasswords are hashed using bcrypt. Groundwork. sign-in flows use session-based authentication, HTTP-only cookies, and email one-time passcode verification after password authentication.
Organization and role boundariesOrganization context and assigned roles are used to limit access. Visibility is further governed by accepted relationships, enabled workflows, permissions, and participant consent.
No Data SellingGroundwork. does not sell or monetize borrower or institution data. Any sharing is handled through the applicable workflow and disclosures.
Deletion requestsBorrowers may request deletion through the platform or by contacting us. Groundwork. processes requests according to its applicable data-handling procedures.
04 · Providers
Provider infrastructure
Managed services support platform hosting, communications, storage, and enabled document workflows within Groundwork's operating controls.
Encrypted at RestPostgreSQL database encrypted at rest on Railway's managed infrastructure.
Managed InfrastructureGroundwork. uses managed hosting and database infrastructure. Service-provider controls support Groundwork's security program but do not independently certify Groundwork's compliance.
Transactional communicationsGroundwork. uses an authorized email service provider for account verification, invitations, and operational notifications.
Enabled document workflowsWhen enabled for an organization, participants may upload requested documents. Authorized service providers may support storage and AI-assisted extraction. Access and use remain limited by the applicable workflow, permissions, disclosures, and approved purpose.
05 · Scope
Compliance and responsibility boundaries
Groundwork. supports partner due diligence but does not replace an institution's legal, regulatory, credit, or vendor-management responsibilities.
GLBA
Groundwork. provides information about its data practices and security controls to support partner review. Each institution determines how GLBA and its vendor-oversight requirements apply to the relationship.
Shared Responsibility
Privacy Rights
Groundwork. responds to applicable requests concerning access, correction, deletion, and sale or sharing. Available rights and exceptions depend on the governing law and circumstances.
As Applicable
NY SHIELD Act
Groundwork. evaluates safeguards for information handled by the platform. Applicability and compliance depend on the information, business scope, and complete administrative, technical, and physical security program.
Control Alignment
Institutional Due Diligence
Groundwork. can provide information to support a credit union's or lender's vendor review. Approval and ongoing oversight remain with the institution under its own policies and applicable guidance.
Partner-Led Review
Fair Lending
Groundwork. organizes readiness information and does not approve, deny, price, or recommend credit. Lenders retain responsibility for underwriting, credit decisions, fair-lending compliance, and their use of participant information.
No Credit Decisions
BSA / AML
Groundwork. does not originate loans, move funds, hold member funds, or perform an institution's identity-verification or transaction-monitoring duties. Each institution determines and fulfills its applicable BSA/AML obligations.
Institution Responsibility
06 · Review

Institutional Due Diligence Materials

Groundwork. can discuss security, privacy, implementation, and contractual documentation during a prospective partner's due diligence process. Materials are provided as applicable to the proposed relationship and approved scope.

MSA
Operations Agreement
Master services agreement covering scope, responsibilities, data ownership, and termination rights.
Request document →
SEC
Security Overview
Technical security controls, encryption standards, access controls, and incident response procedures.
Request document →
PRI
Privacy Policy
Public information about data collection, use, visibility, participant choices, and Groundwork's privacy practices.
View Privacy Policy →
BCP
Business Continuity Plan
Disaster recovery procedures, data backup policies, and service restoration commitments.
Request document →
SOW
Implementation SOW
Statement of work covering onboarding, deliverables, timeline, and acceptance criteria.
Request document →
SLA
Service Level Agreement
Uptime commitments, support response times, and performance standards under the applicable partnership agreement.
Request document →
07 · Planned

Security Roadmap

The items below are planned areas of development, not currently available controls or contractual commitments. Scope and timing may change based on partner needs and implementation priorities.

Planned
Independent SOC 2 Examination
Preparation for an independent examination of controls relevant to security, availability, and confidentiality. Groundwork. does not currently represent that it has completed a SOC 2 examination.
Planned
Single Sign-On (SSO)
SAML 2.0 and OAuth SSO integration for institutions using Microsoft Azure AD, Google Workspace, or Okta. Staff log in with their existing institutional credentials — no separate Groundwork. password required.
Planned
Expanded Audit Reporting
Expanded history for staff access and changes, together with administrative review and export capabilities. Existing organization and role boundaries remain part of the implemented platform controls described above.

Questions about compliance or security?

We're happy to schedule a compliance call with your team, provide additional documentation, or answer any questions about how Groundwork. fits into your institution's vendor management program.

Contact Jerome →