Security & your data
Last updated: August 1, 2026
You're about to hand a stranger your revenue numbers and possibly your bank connection. Here is exactly what happens to all of it, written the way I'd want it written for me.
What we hold
Less than you'd expect, on purpose. Every field we don't collect is a field that can't leak.
- What you type into the applicationYour name, business name and state, email, phone, how much you want, what it's for, your revenue band, time in business, and any funding you already have.
- Basic usage dataWhich pages you saw and how far you got, so I can find where the application confuses people.
- Later, and only if you move forwardDocuments a lender needs to make you an offer, such as bank statements.
We do not ask for your Social Security number or date of birth anywhere on this site. A lender may need identity details at the offer stage, and that happens directly with the lender under its own agreement with you.
What's actually in place
Everything in this list is live right now. I've left out anything I couldn't point at.
- Encrypted in transit, everywhereThe whole site is HTTPS-only and sends a one-year HSTS header with includeSubDomains and preload, so a browser won't fall back to an unencrypted connection.
- Locked-down browser policyA Content Security Policy restricts what can run or connect on these pages to known origins. Forms can only post back to this site. Alongside it: X-Content-Type-Options, a strict referrer policy, and a permissions policy that switches off camera, microphone, geolocation, and payment APIs.
- Your bank token is thrown awayBank connections run through Plaid. The access token is exchanged inside a server-side function, used once to read a masked account label, and then discarded. It's never written to a database, never logged, and never sent to your browser.
- Account numbers stay maskedWhat the system stores and shows is a label like Business Checking ····4821. Full account and routing numbers are never returned to the browser.
- No caching of sensitive responsesEvery server function response is sent no-store, so a browser or proxy won't hold a copy.
- Separate from everything elseFundangle runs on its own infrastructure with its own credentials. It doesn't share a database or a login with any other business I operate.
What we never do
Hard lines
- We don't sell your information to data brokers, lead aggregators, or unrelated advertisers. The parties who receive your details are working on your funding.
- We don't run a credit inquiry without telling you. Nothing here touches your personal credit. A hard pull happens on the lender's side at the offer stage, after you choose to move forward.
- We don't blast your file to every lender we know. It goes to the ones whose stated criteria actually match it.
- We don't keep your bank access. The connection is used once and the token is discarded.
Who else touches your data
Running a funding brokerage means using other companies for hosting, email, and bank connections. Here is the full list, and what each one actually sees. Every vendor below maintains its own independent security attestation.
| Company | What it does for us | What it sees | Their security page |
|---|---|---|---|
| Netlify | Hosts this site and runs its server functions | Form submissions, request logs | Trust center |
| Supabase | Database behind the application and the borrower portal | Application details, offer and portal records | Security |
| Plaid | Bank connection at the offer stage | Your bank login goes to Plaid directly, never to us. We receive a masked account label. | Trust |
| Resend | Sends the emails you get from us | Email address, message contents | Security |
| Close | The system that keeps track of your file | Contact and deal details | Security |
| Google Workspace | Our email and internal documents | Anything you email us | Compliance |
Beyond this list, your details go to the lending partners reviewing your request, and to vetted licensed broker partners only when we can't place your request ourselves. That's covered in the Privacy Policy.
SOC 2
We don't have a SOC 2 report yet, and we won't say we do until one is issued.
A SOC 2 Type I report covering Security and Confidentiality is in progress, targeted for Q1 2027. The Type II observation window starts once Type I is issued.
Your choices
- Get a copy, or have it deletedEmail hello@fundangle.com and say which. We honor deletion requests to the extent the law allows. Records tied to a financing that actually closed have to be kept to meet legal and recordkeeping obligations.
- Stop the contactReply STOP to any text. Email us to stop everything. Calls happen only between 8am and 9pm your local time.
- How long we keep thingsApplication data stays as long as we need it to work your request and meet recordkeeping obligations, then it's disposed of.
Common questions
Do you sell my information?
No. Your details go to parties working to fund your request: our lending partners, and if we can't place your request ourselves, vetted licensed broker partners who may be able to. We don't sell your information to data brokers, lead aggregators, or unrelated advertisers.
Will checking my options affect my credit?
No. Nothing at the top of this process touches your personal credit. A hard inquiry happens on the lender's side, at the offer and underwriting stage, after you've decided to move forward, and you're told before it happens.
Who can see my bank account details?
Nobody here sees your full account or routing numbers. Your bank login goes to Plaid directly and never passes through us. We get back a masked label like Business Checking ····4821, and the access token behind it is discarded rather than stored.
Are you SOC 2 certified?
Not yet. A Type I report covering Security and Confidentiality is in progress, targeted for Q1 2027. We won't claim a report before one is issued.
How do I get my data deleted?
Email hello@fundangle.com and ask. We honor deletion requests to the extent the law allows, with the exception of records tied to a closed financing, which have to be retained.
Found a problem?
If you've found a security issue on this site, email hello@fundangle.com with enough detail to reproduce it. Report it in good faith, don't access or alter anyone else's data while you're looking, and give us a reasonable window to fix it before publishing. There's no bounty program, and I'll credit you if you want the credit.
This page describes our practices and does not constitute legal advice or a warranty. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security. See also our Privacy Policy and Disclosures.