| Area | How O.J. handles it |
|---|---|
| Tenant isolation | Every record belongs to one partner. Queries without a tenant context return nothing. |
| Credentials | OAuth client credentials per environment, with scoped 15-minute tokens. Secrets never reach the browser. |
| SSNs and credit | Owners authorize the soft credit check and enter their SSN only on O.J.’s screen. SSNs are never accepted through the API, and O.J. never shares a score or anything derived from it with partners. |
| Bank data | Bank connections go through Plaid. Partners never see bank logins or balances. |
| Documents | Stored in access-controlled object storage. Every access is logged. |
| Consent | Recorded with a timestamp, terms version and IP address, naming both you and O.J. |
| Submissions | Every lender submission is logged with recipient, time and file version. Your policy can require approval before any submission is sent. |
| Payouts | Destinations are set by a person during onboarding and cannot be changed through the API or MCP. |
| AI | Models extract and classify data from documents. Matching rules are versioned code. When sources conflict, a person reviews the file. |
| Role | O.J. is a commercial loan broker, not a lender. Lenders make all credit decisions. |
Resources
Security
How O.J. protects partner and borrower data.
For vendor-risk reviews, request O.J.’s security packet from developers@meet-oj.com.

