Skip to main content
Book a Demo
Security

Security and Compliance Built Into How timveroOS Runs

timveroOS is deployed in your own environment. Your borrower data never leaves your infrastructure, every change is approved by a person, and everything that runs in production is deterministic and auditable.

  • No Data Egress
  • ISO / SOC 2 Ready Architecture
  • Full Envers Audit
Your Environment
  • AWS
  • Azure
  • Google Cloud
  • On-Premise
timveroOS
  • Borrower Data
  • Keys and Access
  • Code and History
Releases and security patches You approve and install
1 Your Environment

Deployed Where You Decide

  • Your Cloud or Your Data Center

    Your own AWS, Azure or Google Cloud account, or on-premise.

  • Single-Tenant by Design

    Dedicated application instance and isolated database. No shared runtime, no cross-tenant risk.

  • Data Stays in Your Jurisdiction

    You choose the region and the hosting, so residency rules are yours to meet.

  • You Decide When to Update

    New releases arrive as versions you install on your own schedule.

Shared Responsibility

You Own
  • Infrastructure
  • Data
  • Access
  • Encryption Keys
We Provide
  • Software
  • Releases
  • Security Patches
  • Support
  • Backups
  • Disaster Recovery
AI Governance

AI That Builds the System and Never Runs It

  1. Requirements approved before code is written.

  2. Pull request proposed by AI (never touches production).

  3. Tested & reviewed by stakeholders.

  4. Merge approved by engineers and risk.

  5. 100% stored in your repository.

Model-Agnostic

Anthropic Claude by default. Connect any LLM provider (OpenAI, Gemini, Azure OpenAI) under your own contract and API key.

No AI Credit Decisions

Production runs only approved, deterministic logic. The AI never scores borrowers or decides on credit.

2 Assurance

Certifications

  • ISO/IEC 27001:2022

    Information security management system

    In Progress
  • SOC 2

    Independent report on security controls

    In Progress
3 Regulated Lenders

Supporting Your Regulatory Obligations

A self-hosted platform keeps the environment and the data with you, so audits and exit plans don’t depend on a vendor.

  • EU
    • DORA
    • EBA outsourcing guidelines
    • EU AI Act

    The platform runs in your environment, so ICT risk, the register of arrangements and exit plans stay under your control.

  • UK
    • PRA SS2/21
    • FCA SYSC 8
    • Operational resilience

    Outsourcing is simpler to evidence when the system, the data and the change history sit in your own infrastructure.

  • US
    • Interagency TPRM
    • GLBA Safeguards Rule
    • NCUA
    • NYDFS

    Third-party risk reviews cover software you run, not a vendor holding your customer data.

  • Global
    • NIST AI RMF
    • ISO/IEC 42001

    AI generates code and configuration under human approval. It doesn’t score borrowers or make credit decisions.

4 Data Protection

Data Protection and GDPR

Your Role

Controller

Your data is stored and processed in your environment. TIMVERO doesn’t keep borrower data on its side.

TIMVERO Role

Processor

When TIMVERO services your system: access only with your permission, and the DPA is part of the service agreement.

How timveroOS Helps

  • Data Subject Rights

    Find, export and correct a person’s records from one system.

  • Retention

    Keep records only for the periods your policy sets.

  • Deletion

    Audit-backed erasure and anonymization when records reach their retention limit, fully logged in the Envers audit trail.

5 Built In

Compliance Built Into timveroOS

Security is the foundation layer of timveroOS, under every product you build on it. Your exit plan is already in place: the code, the configuration and the change history live in your repository, and the data in your database.

  • Full Audit Trail

    Who changed what and when, with the data before and after.

  • Identity & Access Control

    Multi-role RBAC, granular action permissions, and seamless OIDC/SSO integration (Keycloak, Google).

  • Password Policies

    Configurable password rules for every user of the platform.

  • KYC and AML Frameworks

    Built-in frameworks to run your KYC and AML checks inside the lending flow.

  • Versioned Approved Logic

    Lineage-versioned scripts and mappings. Every rule in production is a reviewed, auditable change.

  • Reproducible Decisions

    The same input gives the same result, and every decision can be explained.

timveroOS, Layer by Layer

Security, with users, roles and the audit trail, is layer 0 under everything you build. Pick a layer to see its building blocks.

Framework-native building blocks: compose, extend, customize

Ops

  • CRM Sublayer

    Launchpad, BI, Views, Pages

    Generic dashboard + Superset

  • Statuses & Labels

    Visual state indicators

    Configurable status mappings

  • API

    REST API, Webhooks

    OpenAPI docs + webhooks

  • BI

    Analytics & Reporting

    Apache Superset integration

Automations

  • Credit Service Framework

    AccrualEngine, Calculations

    Pluggable AccrualEngine + calculation

  • Payment Hub

    Orchestration & Reconciliation

    PaymentGateway + AllocationStrategy

  • Product Engine

    Terms, Conditions & Pricing

    Composable rules + pricing strategies

  • Documents & Intelligence

    OCR, Templates, E-Signatures

    OCR + IDocumentGenerator interface

  • Notifications

    Email, SMS, Push, Voice

    Multi-channel gateway interface

  • History

    Change Tracking, Rollback

    Hibernate Envers + @Audited

  • Covenants

    Monitoring & Compliance

    Scheduled checks + producer-consumer

  • Workflow

    Process Orchestration

    BPMN-like process engine

Dynamic Integration Chain

DataSource Service

External data fetch

Feature Store

Data transformation

Feeds Workflow

State machines as building blocks: extend with custom logic

States

  • Participant States

    Borrower, Co-borrower, Guarantor

    KYC workflow states

  • Asset States

    Collateral lifecycle

    Appraisal → Secured → Released

  • Container States

    Application, Loan

    Full loan lifecycle states

Actions & Events

  • Actions

    Change the states

    Manual transitions

    Type-safe + auto security

  • Events

    Trigger state changes

    Automatic transitions

    Event-driven + pessimistic locking

Forms (Data Entry)

Action Forms

Manual input UI

State Forms

Entity editors

Foundational entities ready to extend with your domain model

Entities

  • Assets

    Collateral, Invoice + Profiles

    • Collateral
    • Invoice

    JPA entity inheritance + dynamic Profiles

  • Participants

    Borrower, Co-borrower, Guarantor + Profiles

    • Borrower
    • Company

    JPA + embedded objects + dynamic Profiles

  • Containers

    Application, Credit, Campaign

    • Application
    • Campaign

    Discriminator pattern

Persistence

Data Model

PostgreSQL

Direct Integration

Core Banking, CRM

Security building blocks with zero custom code

Access & Audit

  • Users & Roles

    Authentication & Authorization

    • User
    • Role
    • Permission

    RBAC + Spring Security

  • Audit Trail

    Security Events & Compliance

    • Who
    • When
    • What

    Security event logging

6 FAQ

Security Questions Lenders Ask

Send Us Your Questionnaire
  • Where is our data stored?

    In your own environment: your cloud account on AWS, Azure or Google Cloud, or your own data center. timveroOS is single-tenant, and TIMVERO doesn’t store your borrower data.

  • Can TIMVERO access our production environment?

    Only if you grant it. When TIMVERO services your system, access is given with your permission and covered by the DPA in the service agreement.

  • Which LLM does timveroAI use, and who chooses it?

    timveroAI is model-agnostic. Anthropic Claude is the default, and you can connect any LLM provider, such as OpenAI, Gemini or Azure OpenAI, under your own contract and API key.

  • Does AI make lending decisions?

    No. The AI proposes changes, people approve them, and production runs only the approved, deterministic logic. The AI doesn’t score borrowers or decide on credit.

  • What is your ISO 27001 and SOC 2 status?

    Both are in progress: ISO/IEC 27001:2022 and SOC 2. In the meantime, we complete your security questionnaire or vendor due diligence pack.

  • What happens to our data and code if we stop working with TIMVERO?

    Nothing moves. The code, the configuration and the change history are already in your repository, and the data is in your database.

Run Your Security Review on timveroOS

Send us your security questionnaire or vendor due diligence pack, or book a demo with the technical team.