Security and Compliance Built Into How timveroOS Runs
timveroOS is deployed in your own environment. Your borrower data never leaves your infrastructure, every change is approved by a person, and everything that runs in production is deterministic and auditable.
- No Data Egress
- ISO / SOC 2 Ready Architecture
- Full Envers Audit
- AWS
- Azure
- Google Cloud
- On-Premise
- Borrower Data
- Keys and Access
- Code and History
Deployed Where You Decide
-
Your Cloud or Your Data Center
Your own AWS, Azure or Google Cloud account, or on-premise.
-
Single-Tenant by Design
Dedicated application instance and isolated database. No shared runtime, no cross-tenant risk.
-
Data Stays in Your Jurisdiction
You choose the region and the hosting, so residency rules are yours to meet.
-
You Decide When to Update
New releases arrive as versions you install on your own schedule.
Shared Responsibility
- Infrastructure
- Data
- Access
- Encryption Keys
- Software
- Releases
- Security Patches
- Support
- Backups
- Disaster Recovery
AI That Builds the System and Never Runs It
-
Requirements approved before code is written.
-
Pull request proposed by AI (never touches production).
-
Tested & reviewed by stakeholders.
-
Merge approved by engineers and risk.
-
100% stored in your repository.
Model-Agnostic
Anthropic Claude by default. Connect any LLM provider (OpenAI, Gemini, Azure OpenAI) under your own contract and API key.
No AI Credit Decisions
Production runs only approved, deterministic logic. The AI never scores borrowers or decides on credit.
Certifications
- In Progress
ISO/IEC 27001:2022
Information security management system
- In Progress
SOC 2
Independent report on security controls
Supporting Your Regulatory Obligations
A self-hosted platform keeps the environment and the data with you, so audits and exit plans don’t depend on a vendor.
- EU
- DORA
- EBA outsourcing guidelines
- EU AI Act
The platform runs in your environment, so ICT risk, the register of arrangements and exit plans stay under your control.
- UK
- PRA SS2/21
- FCA SYSC 8
- Operational resilience
Outsourcing is simpler to evidence when the system, the data and the change history sit in your own infrastructure.
- US
- Interagency TPRM
- GLBA Safeguards Rule
- NCUA
- NYDFS
Third-party risk reviews cover software you run, not a vendor holding your customer data.
- Global
- NIST AI RMF
- ISO/IEC 42001
AI generates code and configuration under human approval. It doesn’t score borrowers or make credit decisions.
Data Protection and GDPR
Controller
Your data is stored and processed in your environment. TIMVERO doesn’t keep borrower data on its side.
Processor
When TIMVERO services your system: access only with your permission, and the DPA is part of the service agreement.
How timveroOS Helps
-
Data Subject Rights
Find, export and correct a person’s records from one system.
-
Retention
Keep records only for the periods your policy sets.
-
Deletion
Audit-backed erasure and anonymization when records reach their retention limit, fully logged in the Envers audit trail.
Compliance Built Into timveroOS
Security is the foundation layer of timveroOS, under every product you build on it. Your exit plan is already in place: the code, the configuration and the change history live in your repository, and the data in your database.
-
Full Audit Trail
Who changed what and when, with the data before and after.
-
Identity & Access Control
Multi-role RBAC, granular action permissions, and seamless OIDC/SSO integration (Keycloak, Google).
-
Password Policies
Configurable password rules for every user of the platform.
-
KYC and AML Frameworks
Built-in frameworks to run your KYC and AML checks inside the lending flow.
-
Versioned Approved Logic
Lineage-versioned scripts and mappings. Every rule in production is a reviewed, auditable change.
-
Reproducible Decisions
The same input gives the same result, and every decision can be explained.
timveroOS, Layer by Layer
Security, with users, roles and the audit trail, is layer 0 under everything you build. Pick a layer to see its building blocks.
Framework-native building blocks: compose, extend, customize
Ops
-
CRM Sublayer
Launchpad, BI, Views, Pages
Generic dashboard + Superset
-
Statuses & Labels
Visual state indicators
Configurable status mappings
-
API
REST API, Webhooks
OpenAPI docs + webhooks
-
BI
Analytics & Reporting
Apache Superset integration
Automations
-
Credit Service Framework
AccrualEngine, Calculations
Pluggable AccrualEngine + calculation
-
Payment Hub
Orchestration & Reconciliation
PaymentGateway + AllocationStrategy
-
Product Engine
Terms, Conditions & Pricing
Composable rules + pricing strategies
-
Documents & Intelligence
OCR, Templates, E-Signatures
OCR + IDocumentGenerator interface
-
Notifications
Email, SMS, Push, Voice
Multi-channel gateway interface
-
History
Change Tracking, Rollback
Hibernate Envers + @Audited
-
Covenants
Monitoring & Compliance
Scheduled checks + producer-consumer
-
Workflow
Process Orchestration
BPMN-like process engine
Dynamic Integration Chain
DataSource Service
External data fetch
Feature Store
Data transformation
Feeds Workflow
State machines as building blocks: extend with custom logic
States
-
Participant States
Borrower, Co-borrower, Guarantor
KYC workflow states
-
Asset States
Collateral lifecycle
Appraisal → Secured → Released
-
Container States
Application, Loan
Full loan lifecycle states
Actions & Events
-
Actions
Change the statesManual transitions
Type-safe + auto security
-
Events
Trigger state changesAutomatic transitions
Event-driven + pessimistic locking
Forms (Data Entry)
Action Forms
Manual input UI
State Forms
Entity editors
Foundational entities ready to extend with your domain model
Entities
-
Assets
Collateral, Invoice + Profiles
JPA entity inheritance + dynamic Profiles
-
Participants
Borrower, Co-borrower, Guarantor + Profiles
JPA + embedded objects + dynamic Profiles
-
Containers
Application, Credit, Campaign
Discriminator pattern
Persistence
Data Model
PostgreSQL
Direct Integration
Core Banking, CRM
Security building blocks with zero custom code
Access & Audit
-
Users & Roles
Authentication & Authorization
RBAC + Spring Security
-
Audit Trail
Security Events & Compliance
Security event logging
Security Questions Lenders Ask
Send Us Your Questionnaire-
Where is our data stored?
In your own environment: your cloud account on AWS, Azure or Google Cloud, or your own data center. timveroOS is single-tenant, and TIMVERO doesn’t store your borrower data.
-
Can TIMVERO access our production environment?
Only if you grant it. When TIMVERO services your system, access is given with your permission and covered by the DPA in the service agreement.
-
Which LLM does timveroAI use, and who chooses it?
timveroAI is model-agnostic. Anthropic Claude is the default, and you can connect any LLM provider, such as OpenAI, Gemini or Azure OpenAI, under your own contract and API key.
-
Does AI make lending decisions?
No. The AI proposes changes, people approve them, and production runs only the approved, deterministic logic. The AI doesn’t score borrowers or decide on credit.
-
What is your ISO 27001 and SOC 2 status?
Both are in progress: ISO/IEC 27001:2022 and SOC 2. In the meantime, we complete your security questionnaire or vendor due diligence pack.
-
What happens to our data and code if we stop working with TIMVERO?
Nothing moves. The code, the configuration and the change history are already in your repository, and the data is in your database.
Run Your Security Review on timveroOS
Send us your security questionnaire or vendor due diligence pack, or book a demo with the technical team.