Trust Center

What we know. What we're working on. Where the gaps are.

In plain terms: an honest snapshot of what Debt Digest can prove today, and what is still in progress.

This page is for the compliance and risk officer who has to sign off on us. We will not pretend the SOC 2 is finished, that our state-by-state conduct review is complete, or that our break-glass procedure is mature. Below is exactly where we stand, dated, with the documents you would need to redline our pilot agreement.

Role and authority recorded per account Charge-off aligned · NCUA & FFIEC SOC 2 in progress
The four commitments

What we will not change on you mid-pilot.

These are the institutional anchors. Everything else on this page is qualified by date and status. These four are not.

Member funds never touch us

Consumers pay the identified account owner or authorized payee. Participating organizations pay Debt Digest by subscription invoice. For currently activated direct-payment workflows, Debt Digest does not custody consumer funds. We host the shared record, enforce configured controls, and preserve the audit trail.

FDCPA + Reg F controls in the send path

Where the consumer’s state is on file, the text path holds a message outside that consumer’s local calling window; where it is not, an Eastern-time window applies as the fallback. It checks a §1692c(c) cease-communication mark before it sends. Where the identity fields are on file, the text path also checks the outbound against the §805(a)(2) representation list, and a representation block is written to its own firewall record with the channel and the tenant that attempted it.

Append-only audit log, exportable

Every state change emits a tamper-evident log entry. You can export the full chain for your portfolio in CSV at any time, with no gating and no notice required.

72-hour breach notification

If we detect an incident that may affect your data, you hear from us in writing within 72 hours of detection. Post-incident report within 30 days. Direct line to the on-call engineer during the active window.

Where we are on the journey

Regulatory posture, today.

SOC 2 readiness work is underway in-house; we are not attested today. We are committed to additional certifications as we onboard customers who require them. Our per-state conduct review follows pilot footprint.

Participant posture is account-specific
Debt Digest records the account owner, creditor, servicer, collector, firm, representative, sender, and decision-maker separately. Legal duties follow actual role, authority, conduct, account context, jurisdiction, and law, not a platform-wide label or funds-flow shortcut. The control model is described on /legal for your counsel.
SOC 2 in progress
Readiness work is underway in-house. No audit firm is engaged yet and we are not attested today; we will not market as if we were. Status updates are published on this page as they land, and compliance certifications scale with customer requirements.
Counsel of record
Outside compliance counsel engagement is in progress. The regulatory analysis is drafted and dispatch-ready in-house; counsel is retained at defined triggers, the first of which is a first pilot signature. Counsel name is published here once the engagement letter is countersigned.
Pen test on the program
Third-party penetration test on the program before first production pilot. SSO and SAML federation on the roadmap.
State review

Available in every state. Reviewed state by state.

Debt Digest is receivables workflow software. It does not collect, does not contact consumers in its own name, and holds no state collection license; in each state we review whether one is needed before a customer goes live. Federal status is settled by conduct, not by category. State statutes are a separate question because some define collection activity more broadly than federal law, so we review each state on the same two questions: does the statute reach what the software actually does, and which licenses does the customer using it there already carry. Where a review is still open we say so. The current federal and state analysis lives on /legal.

State Our conduct review What it found, and who carries the license
Texas Reviewed in-house Primary pilot footprint. Our working analysis, not yet counsel-confirmed, is that under Tex. Fin. Code Ch. 392 the software is not a person engaged in debt collection: a creditor is first-party on its own debt, and an agency or firm customer carries its own registration. The rescoped opinion goes to outside counsel at the first pilot signature in this state.
Georgia Reviewed in-house Our working analysis, not yet counsel-confirmed, is that under O.C.G.A. § 7-3-26 the software is not a person engaged in the collection of consumer debt. Any collection licensing sits with the customer acting on the accounts. The rescoped opinion goes to outside counsel at the first pilot signature in this state.
Ohio Reviewed in-house Our working analysis, not yet counsel-confirmed, is that under Ohio Rev. Code Ch. 1349 and Ch. 4710 the software is outside both the collection and the debt-adjustment definitions: it never holds consumer funds and never demands payment in its own name. The rescoped opinion goes to outside counsel at the first pilot signature in this state.
Florida Under review Fla. Stat. § 559.553 registers consumer collection agencies. An agency customer holds that registration; a creditor customer is first-party. Whether any reading of the statute reaches the software itself is the open question, and we write it down before a Florida customer goes live.
North Carolina Under review N.C. Gen. Stat. § 58-70-1 et seq. permits collection agencies. The customer acting on accounts carries the permit. The written analysis of whether the statute reaches the software is open.
New York Under review N.Y. Gen. Bus. Law § 600 and the NYC Department of Consumer and Worker Protection license attach to the party contacting the consumer, which is the customer. Section 600 can also be read to reach a facilitator, which is why New York stays Under review until the written answer lands, before any New York customer goes live.
California Under review The Debt Collection Licensing Act licenses debt collectors. A creditor customer is first-party on its own debt and an agency customer holds its own DFPI license. Whether the Act reaches a workflow vendor by conduct is under written review; we assume neither an exclusion nor a filing until it is complete.
All other states Reviewed at first customer The software is available. The per-state written review is completed when the first customer in that state signs, because that is when the participant roles and conduct in that state are concrete rather than hypothetical.

Prepared and maintained in-house against current state law. Submitted for outside-counsel review at the first pilot signature in a given state, and revisited on any state regulatory action.

Open questions we are willing to be asked

The questions we want compliance officers to ask first.

If a vendor doesn't surface these for you, they're either young enough not to have thought about them or mature enough to be hiding them. We are the first. Here are the honest answers.

Who has production database access today?
Founder only, until the first hire. Credentials rotate on every new hire. Break-glass procedure is documented with one external trustee and will expand when the team does. This is small-team posture, not best-practice posture, and we name it as such.
What happens if hosted compute or our managed database has an outage?
Runbook is published. Target RTO is 4 hours; RPO is 15 minutes via managed-Postgres point-in-time recovery. We have not yet tested a full region-loss restore against a clean infrastructure rebuild; that exercise is scheduled before first production pilot go-live.
What happens if the founder is unavailable?
Break-glass access is documented with one external trustee. Continuity is single-point-of-failure-bound until the first engineering hire. We disclose this in the pilot agreement; we do not paper it over.
Can we run a penetration test before signing?
Yes. We will coordinate with your preferred firm, cover standard scope, and accept reasonable remediation conditions in the pilot agreement. We expect this; the pen test is itself part of our pre-production checklist.
What is your E&O insurance coverage today?
We are sourcing professional liability and cyber-incident coverage now, timed to bind at the first production pilot. We expect $1M / $2M aggregate at first bind; we will share the binder with the pilot agreement. Today: not yet bound. Stating this directly is the point of this page.
Have you been the subject of a regulatory complaint?
No. As of this writing we have placed zero accounts in production. We will publish complaint counts here from the day a first complaint arrives, with date and resolution, per quarter.
Known gaps and what we are doing

The work in progress, named.

A vendor who claims no gaps is a vendor who hasn't audited themselves. Here are ours, what's in motion, and when we expect each to clear.

SOC 2 attestation
SOC 2 is in progress. We are not attested today and will not market as if we were. Status updates appear on this page as they land.
SSO and SAML federation
On the roadmap. Until then, creditor users authenticate with JWT-backed sessions (4-hour expiry, scrypt-hashed passwords). Not enterprise-grade for federated identity; named as such.
Continuous penetration testing cadence
A third-party pen test lands before any real account data is in the system, with continuous cadence thereafter. We have not yet completed a paid external pen test as of today.
Multi-region disaster recovery
Single-region today (US-East). Multi-region active-passive is on the roadmap; we will not pretend we have it today. Point-in-time recovery and tested backups are in place for the single region.
Formal third-party risk program
Hosted infrastructure runs on SOC 2 Type II sub-processors. Three receive data today: application compute and edge, the managed database, and source control and CI. Payment processing and transactional email and SMS are contracted but not enabled and receive nothing. We run no separate error-tracking provider, and no separate CDN or web-application-firewall provider; authoritative DNS is hosted at Google Cloud DNS, which resolves names only. The formal vendor-risk-management policy with annual review attestations lands with SOC 2 fieldwork.
Dedicated CISO or compliance officer
Founder-led today. The Chief Compliance Officer role is in the post-pilot hiring plan and is a hard prerequisite before scaling beyond pilot. Outside compliance counsel is retained at defined triggers in the meantime, the first of which is a first pilot signature.
Counsel of record & statute index

Who supervises this, and which statutes we operate under.

Pilot agreement redlines are welcome. Once counsel is retained at signature, our counsel and your counsel speak directly; we don't sit between them.

Counsel contacts

Counsel of record

Outside compliance counsel is retained at defined triggers, the first of which is a first pilot signature. The scope is already set: FDCPA and Reg F posture, charge-off timing (NCUA 12 CFR 741.3 for credit unions, FFIEC URCC for banks), and state-licensing matters. That analysis is drafted and dispatch-ready today. Firm name is disclosed under NDA during diligence once the engagement letter is countersigned.

Redline our pilot agreement

Send your standard markup to legal@debt-digest.com. We turn redlines within five business days. Non-trivial changes are held for outside-counsel review at engagement.

Statute index

FDCPA §809(a) Applicable validation-notice workflow FDCPA §805(a)(2) Counsel firewall FDCPA §1692c(c) Cease-communication, one-click Reg F §1006.6 Outreach time-of-day windows Reg F §1006.34 Applicable validation information and itemization NCUA 12 CFR 741.3 120-DPD charge-off boundary (credit unions) OCC / FFIEC 180-day charge-off boundary (banks) RFC 9116 security.txt disclosure contact

Transport & infrastructure controls

TLS 1.3 All traffic encrypted in transit HSTS Strict-Transport-Security enforced Hosted compute SOC 2 Type II sub-processor Managed Postgres SOC 2 Type II sub-processor Source control and CI SOC 2 Type II sub-processor

For the printable one-page packet with the encryption controls and sub-processor categories, see /security.

Changelog

What changed on this page, when.

Material edits to commitments, licensing posture, or counsel are dated below. Cosmetic edits are not.

Effective
Review cadence
Quarterly
v1.52026-08-13: Sub-processor description reconciled against the running production environment and against our Data Processing Agreement. Three providers receive data today: application compute and its edge, the managed database, and source control and CI. Payment processing and transactional email and SMS are contracted but not enabled and receive nothing. Removed a separate edge/DDoS provider and an error-tracking provider, neither of which we engage. Disclosed Google Cloud DNS by name.
v1.42026-07-24: Corrected counsel and audit status. Prior wording stated that outside compliance counsel was engaged and that a SOC 2 audit engagement was active; neither was accurate. Outside counsel is retained at defined triggers, the first of which is a first pilot signature, and SOC 2 readiness work is in-house with no audit firm engaged. Removed an outside-counsel review date on the state-licensing table that did not correspond to a review. Restated the E&O timing against first production pilot rather than entity formation, which has closed.
v1.32026-05-18: Restructured page from a single-column control list into the honest open-questions format. Added state-licensing table, gaps section, and counsel block. Moved the printable control summary to /security.
v1.22026-04-21: Added 72-hour breach notification commitment to the four institutional pillars. Refreshed compliance posture.
v1.12026-04-08: Added state-by-state posture list (TX, GA, OH). Confirmed payment-flow firewall: consumer → creditor → DD.
v1.02026-04-06: Initial publication alongside the accessibility and compliance hardening sprint.
Data handling and incident response

How member data moves through us, and what happens if something breaks.

The printable controls list lives on /security. The posture statements below describe what we will and will not do with your members' data.

How member data moves

FDCPA §809 Validation Reg F §1006.6 Quiet hours FDCPA §805(a)(2) Counsel firewall

Member data flows through one tenant boundary per creditor.

PII firewalls are enforced at the database query layer, not application policy. A creditor cannot read another creditor's members. We never sell data. We never share member PII across pilots. Minimum-necessary is the rule: last-4 SSN where ID verification requires it; full SSN never requested for servicing. Closed accounts anonymized after 7 years per FDCPA record-keeping norms. Creditors can export their full audit log and portfolio in CSV at any time, with no gating.

GDPR / NCUA 72-hour notice RFC 9116 security.txt

If we detect an incident, you hear from us in writing within 72 hours.

Post-incident report within 30 days covers root cause, scope, remediation, and prevention. You get direct access to the on-call engineer during the active window. Security contact: security@debt-digest.com. Coordinated-disclosure contact is published at /.well-known/security.txt per RFC 9116.

Bring your hardest compliance question.

We would rather you ask now and walk away than learn the answer in month three of a pilot. If we have not addressed it on this page, send it directly.