FAQ
Compliance
Scroll
What our compliance program runs
This section is exported from Vanta — the platform that continuously monitors our security controls — last refreshed 2026-09-03. It is generated from the program itself, so it cannot say more than the program does.
-
HIPAA
Business AssociateAdministrative, physical and technical safeguards for protected health information, operated and continuously monitored under the same compliance program.
-
SOC 2 Type II
SecuritySweet maintains a SOC 2 Type II attestation. The report is available to prospective customers under NDA.
Policy register The approved policies our program maintains, named as they exist in Vanta.
- Access Control Policy To limit access to information and information processing systems, networks, and facilities to authorized parties in accordance with business objectives.
- Asset Management Policy To identify organizational assets and define appropriate protection responsibilities. To ensure that information receives an appropriate level of protection in accordance with its importance to the organization. To prevent unauthorized disclosure, modification, removal, or destruction of information stored on media.
- Business Continuity and Disaster Recovery Plan The purpose of this business continuity plan is to prepare SweetTech in the event of extended service outages caused by factors beyond our control (e.g., natural disasters, man-made events), and to restore services to the widest extent possible in a minimum time frame.
- Code of Conduct Develops and maintains a standard of conduct that is acceptable to the company and its employees, customers, and vendors.
- Cryptography Policy To ensure proper and effective use of cryptography to protect the confidentiality, authenticity and/or integrity of information. This policy establishes requirements for the use and protection of cryptographic keys throughout their entire lifecycle.
- Data Management Policy To ensure that information is classified, protected, retained and securely disposed of in accordance with its importance to the organization.
- Human Resource Security Policy To ensure that personnel and contractors meet security requirements, understand their responsibilities, and are suitable for their roles.
- Incident Response Plan This document establishes the plan for managing information security incidents and events, and offers guidance for employees or incident responders who believe they have discovered, or are responding to, a security incident.
- Incident Response Plan HIPAA Addendum with Breach Notification Procedures This HIPAA policy addendum details SweetTech's procedures when a potential breach of ePHI has been identified.
- Information Security Policy (AUP) The purpose of this policy is to communicate our information security policies and outline the acceptable use and protection of SweetTech’s information and assets.
- Information Security Roles and Responsibilities This policy and associated guidance establish the roles and responsibilities within SweetTech, which is critical for effective communication of information security policies and standards.
- Network and System Hardening Standards Policy governing the network and systems hardening principles.
- Operations Security Policy To ensure the correct and secure operation of information processing systems and facilities.
- Physical Security Policy To prevent unauthorized physical access or damage to the organization’s information and information processing facilities.
- Risk Management Policy To define the methodology for assessing and managing SweetTech’s information security risks in order to achieve the company’s business and information security objectives.
- Secure Development Policy To ensure that information security is designed and implemented within the development lifecycle for applications and information systems.
- Third-Party Management Policy To ensure protection of the organization's data and assets that are shared with, accessible to, or managed by suppliers, including external parties or third-party organizations such as service providers, vendors, and customers, and to maintain an agreed level of information security and service delivery in line with supplier agreements.
Is our data secure? What attestations do you hold?
Sweet maintains a SOC 2 Type II attestation and the report is available to prospective customers under NDA. Data is encrypted in transit and at rest, and your institution's data is segregated from every other customer's. The security page sets out the current position in the detail a third-party risk questionnaire asks for.
Link to this answer
Who can see our borrowers' data?
Your data is yours. It is encrypted, and your institution's data is segregated from every other customer's. It is not pooled. The team comes from a fintech and banking background and treats data security as a starting condition rather than a feature. Access control, retention and sub-processors are documented on the security page.
Link to this answer
Can we control what the borrower sees, or keep things internal (e.g., not expose pricing/eligibility)?
Yes. Eligibility, pricing, and decisioning can be kept internal to the loan officer, and lenders can self-restrict what borrowers can do.
Link to this answer
Do you generate loan documents and disclosures?
Yes. Custom document generation works alongside the lender's disclosure vendors where required.
Link to this answer
Is e-signature embedded and tamper-proof? Can we put an NDA first, and how is signing/vaulting handled?
Sweet ships its own embedded e-signature, fully integrated into the platform: HSM tamper-sealing, two signature options, and an NDA available as the first gating task. The platform also integrates with e-vaulting (eOriginal/Wolters Kluwer) for authoritative copies.
Link to this answer
How is our customers' data protected?
Encryption in transit and at rest, segregation of your institution’s data from every other customer’s, and a SOC 2 Type II attestation covering the controls behind both. Hosting, the sub-processor list, data isolation and Sweet’s incident-notification commitments are set out on the security page; retention windows and notification timelines are set in each institution’s agreement, and further detail is available to your risk team on request.
Link to this answer
Can you pull financials from other institutions (Plaid) and verify identity?
Yes. Connectors for financial data, plus multiple ID-verification options (SMS/carrier PII, driver's-license scan, KBA).
Link to this answer
See the platform on your own book of business.
A working demo with your loan programs, your documents, and your workflow, not a slide deck.