Trust

Security at Cap Fi

Financing files contain sensitive business and personal information. Here is how we handle yours.

Private client portal

Every client has an individual login. Documents, application status, offers and messages are scoped to that account, so one client cannot see another client's file.

Administrative access is limited to Cap Fi's Managing Director.

Document storage

Uploaded documents such as bank statements, tax returns and identification are stored in a private, non-public storage bucket. They are never served from a public URL.

When you or an administrator open a document, the system issues a short-lived, single-purpose link that expires within minutes.

Sensitive identifiers

Where you authorize a credit review, the identifying information required for that request is encrypted before it is stored and is not displayed back in the portal.

Encryption in transit

The website and portal are served over HTTPS, so information you submit is encrypted between your browser and our systems.

Access and deletion

Client accounts are created by Cap Fi rather than through open self-registration. If you no longer want your account, we can permanently delete it and the documents attached to it on request.

What we ask of you

Use a strong, unique password for the portal and do not share your login. Cap Fi will never ask for your portal password by phone, text or email.

Upload documents through the portal rather than email whenever possible.

Reporting a concern

If you believe you have found a security issue with this site or the client portal, contact us before sharing it publicly. Email Christopher@capficapital.com or call (804) 774-5101. We will acknowledge your report and work with you on a fix.