Security & trust

Security you can interrogate

Lending data deserves specifics, not adjectives. Here is what actually protects a book on Loano — the controls, where they run, and the straight answers to the questions security reviews ask.

The controls

What protects the data

Encryption at rest

Sensitive borrower fields and every provider credential are encrypted at rest; all traffic runs over HTTPS with certificates issued and renewed automatically.

PII masked by default

PAN, Aadhaar, DOB and contact details render masked behind an eye toggle — seeing the full value is a deliberate, permission-gated act.

Roles + per-user grants

Seeded role desks with least-privilege defaults, plus per-user permission grants for exceptions — the effective access set is visible on one screen.

Two-layer audit trail

A readable action log plus field-level before/after diffs, written by the platform core — features cannot opt out of the record.

Maker-checker on money

Disbursals require separate preparing and approving hands, with reasoned send-backs — no single person moves money alone.

Tenant isolation

Each entity’s data is scoped per tenant in the data layer; row-level visibility scopes desks within a tenant on top of that.

Stage locks

Edit windows per role and lifecycle stage — approved and disbursed files can’t be casually modified by anyone who happens to open them.

Export governance

Data downloads are page-wise permissions granted per user — there is no single “export everything” switch to leak a book through.

Hosted in India

Infrastructure runs in India, in line with where lending data should live, with staff login controls — enforced login modes, leave-aware access and login history.

Straight answers

The questions security reviews actually ask

Does Loano touch borrower money?No. Loano prepares payout files and reconciles collections; funds move between the borrower and the lender’s own accounts on your configured rails.
Whose provider accounts run the integrations?Yours. Bureau, payment, KYC and e-sign credentials belong to your entity, are encrypted at rest, and can be rotated or replaced by you.
Who owns the data?You do. Contractual exit includes your data returned in a usable format with a defined transition window.
Are you ISO / SOC certified?We don’t wave badges we don’t hold. Today we document our controls directly and answer security questionnaires in specifics — ask us anything.
Can your staff see our book?Platform-side access is limited, deliberate and logged — the same audit discipline the product enforces applies to its operators.
What about compliance itself?Loano provides workflow controls and records; regulatory compliance remains the responsibility of the regulated entity. We build so that your answers are easy to give.

Send us your security questionnaire

We answer in specifics, control by control — and show you each one running in the product.

Book a demo