Security Overview

Last updated: May 28, 2026

1. Platform Security Posture

Caplift is built around layered controls for authentication, validation, compliance gating, auditability, and controlled access to marketplace and underwriting workflows. The platform is designed to favor deterministic and explainable behavior over opaque or uncontrolled automation.

2. Access Control

Access to sensitive features is derived from authenticated user state, role, account tier, and compliance metadata enforced at the server level. Institutional and marketplace features (currently under development) are designed to require verified investor status, jurisdiction eligibility, and compliance clearance before any access is granted. These controls are enforced server-side and are not bypassable through client-side state.

3. Verification and Compliance Controls

Investor onboarding includes staged identity, accreditation, KYC/AML, disclosure, and signature workflows. Additional suitability, jurisdiction, target-market, explainability, reserve-control, and audit constraints are applied in specific marketplace and structured-credit flows.

4. Application and API Protections

Caplift implements CORS restrictions, security-header configuration, validation limits, audit logging, and deterministic fallback behavior for degraded external services. Production systems use hardened hosting, secrets management, monitoring, and infrastructure controls.

5. Auditability

Caplift includes structured audit logging and durable control logging patterns for key compliance, reserve, and transactional workflows. These controls are intended to support internal review, incident response, regulatory examination readiness, and investor diligence.

6. Important Limitations

No system can guarantee full legal or security compliance across all jurisdictions. Formal readiness depends on configuration, vendor management, access governance, incident response, penetration testing, legal documentation, data mapping, retention enforcement, and independent review.

7. Reporting

Security concerns may be reported to admin@caplift.ca.

Submit a Security Report

Submit a security concern or vulnerability report.

© 2026 Caplift Financial Inc.
Disclosures: Caplift provides software, workflow support, and informational outputs. Final financing, investment, and compliance decisions require human review.