NorthstarTrust centreLive system status

Security, privacy, and reliability

Trust should be verifiable.

Northstar only uses the information an applicant agrees to share. Access is limited, and every staff decision is recorded.

Tenant isolation

Organization membership and row-level policies separate customer records. Privileged server routes repeat authorization checks.

Encrypted provider tokens

Bank-provider access tokens remain server-only and are encrypted before storage.

Append-only evidence

Consent, decisions, administrative changes, approvals, and settlement actions create audit records.

Data minimization

Operational analytics exclude applicant financial values. Support diagnostics exclude credentials, tokens, and full account numbers.

Privileged MFA

Sensitive owner, approval, and payment actions can require an authenticator-verified session.

Operational resilience

Northstar checks incoming updates, safely retries interrupted work, and clearly flags anything that needs attention.

Data lifecycle

Set how long data is kept and handle access, corrections, consent withdrawal, and deletion requests.

Responsible claims

Northstar does not display certification badges unless the corresponding assessment and approval are complete.

Applicant transparency

Applicants see purpose, requested data, recipient, retention information, and a record of their consent.