Tenant isolation
Organization membership and row-level policies separate customer records. Privileged server routes repeat authorization checks.
Security, privacy, and reliability
Northstar only uses the information an applicant agrees to share. Access is limited, and every staff decision is recorded.
Organization membership and row-level policies separate customer records. Privileged server routes repeat authorization checks.
Bank-provider access tokens remain server-only and are encrypted before storage.
Consent, decisions, administrative changes, approvals, and settlement actions create audit records.
Operational analytics exclude applicant financial values. Support diagnostics exclude credentials, tokens, and full account numbers.
Sensitive owner, approval, and payment actions can require an authenticator-verified session.
Northstar checks incoming updates, safely retries interrupted work, and clearly flags anything that needs attention.
Set how long data is kept and handle access, corrections, consent withdrawal, and deletion requests.
Northstar does not display certification badges unless the corresponding assessment and approval are complete.
Applicants see purpose, requested data, recipient, retention information, and a record of their consent.