Security

Last updated: 28-07-2026

Security by Design

Security forms an integral part of the design and development of the Credimigo platform ("security & privacy by design and by default").

Security measures

Credimigo applies, among others, the following measures:

  • TLS encryption for data in transit;
  • encrypted storage of data at rest;
  • audit logging of important actions within the Platform;
  • role-based access control;
  • tenant isolation between customer environments;
  • rate limiting to prevent abuse and overload;
  • automatic backups;
  • continuous monitoring;
  • automated fraud detection.

Multi-Tenant Security

Every organisation using the Platform has a logically fully separated environment ("tenant"). Users only have access to data for which they are authorised within their organisation.

AI Security

AI is used within the Platform for, among other things, communication, classification, translations and recommendations. AI does not take autonomous legal decisions without human approval. Output from AI systems is, where relevant, logged for the purposes of auditability and quality assurance. Credimigo periodically evaluates the accuracy and integrity of the AI models used.

Incident response

Credimigo has internal procedures for detecting, assessing and handling security incidents, including escalation paths and, where applicable, the notification obligation as described in the Data Processing Agreement.

Responsible Disclosure

Security researchers who discover a vulnerability in good faith and without harming the confidentiality, integrity or availability of data or systems are requested to report it responsibly via: security@credimigo.com. Credimigo strives to confirm and resolve reported vulnerabilities within a reasonable period and, provided the reporter has acted in good faith in accordance with this paragraph, will not take legal action against the reporter.

Contact

For other questions about security: info@credimigo.com.