Security posture, trust documentation, responsible disclosure, and operational resilience — in one place. Titledeep is designed to protect sensitive identity and financial data through controlled access, encryption, secure storage, and traceable actions.
Titledeep maintains security policies and procedures covering access reviews, secure development practices, vulnerability management, incident response, and third-party risk management. Governance artefacts are available for enterprise partners on request, subject to confidentiality.
Where independent testing or certification is conducted (for example, penetration tests or control attestations), Titledeep can provide summary materials to enterprise partners under appropriate confidentiality terms. We avoid claiming certifications unless formally achieved and in scope for the service.
Titledeep uses carefully selected service providers to operate the platform (for example, hosting, communications, monitoring). We maintain a sub-processor inventory including purpose, data categories, locations, and effective dates. Write to us to request the latest sub-processor list.
Titledeep may use automation to extract fields from documents, highlight inconsistencies, and suggest next actions. Automation is designed to support accuracy and speed, not to replace regulated decision-making. Banks and authorised parties make credit decisions, set pricing, and issue approvals.
If you believe you have found a security issue, report it responsibly to security@titledeep.com. Please avoid submitting or exposing personal data beyond what is necessary to demonstrate the issue.