Security and compliance

Controls for lender-owned borrower data and human review.

The platform is built around role scope, company scope, auditability, borrower consent points, and explicit AI decision-support boundaries.

Controls

What lenders can review before production setup.

01

Role-based access

Admin, manager, staff, and viewer roles combine with staff-level permission triples for module, feature, and action-level control.

02

Company scoping

Staff can be scoped to one company or a controlled set of company units, while admins manage the group-level view.

03

Audit logs

Sensitive lookup, chat queries, profile edits, sync actions, and admin changes are recorded for operational traceability.

04

HKID and phone handling

Exact-HKID search is permission-scoped and audit-logged. Phone display is masked where the user context requires it.

05

Borrower consent

Marketplace and loan request flows preserve selected-lender consent, so lenders receive requests the borrower chose to share.

06

AI boundaries

AI outputs are decision-support tools for human review. Admin-only edits require proposal, confirmation, application, and audit logging.

07

PDPO-aligned handling

Product setup maps borrower consent points, staff access, data retention expectations, and lender data ownership before rollout.

08

CDS preparation

Covenant Desk structures application, approved terms, and repayment records for lender export ahead of the rules effective 1 June 2027.

Covenant Desk borrower tracking workspace on a laptop
Operating boundary

Covenant Desk supports lender compliance work; it is not legal advice.

The product helps lenders organize records, access, audit, exports, and review workflows. Lenders remain responsible for regulatory interpretation, borrower suitability, credit approval, and submission obligations.