Contact Us Join Sign In

Certification Quiz & Guidelines

Instant feedback — including vulnerability detection.

Program Scope

Guidelines are for deal-processing roles (e.g. underwriters, sales, etc.)

No specific software is required. The program is focused on the initial submission package, where unauthorized use most often occurs. If the files are downloadable rather than view-only, we verify that safeguards are in place, or help you implement them. The goal is to reduce the ability to move downloaded files outside the company.

How It Works

  • Submit request to join
  • Receive portal access and member #
  • Listed in directory as an Applicant, newsletter and social announcements
  • Upload evidence within 90 days — extensions & support available
  • Get Certified — directory updated, digital badge issued, certification announced

Path to Certification

Join, then work toward certification with our support or self-service. The process is collaborative and focused on helping you meet the standard rather than finding reasons for disqualification.

1. Submission Protection

How do brokers submit deals to you?
Select all that apply.
System of Record
Are the submission documents view-only, or downloadable?

View-only access meets this requirement. The standard applies to the initial submission package, not routine supplemental documents exchanged later in the funding process.

Downloadable documents need a safeguard to reduce the ability to move them outside company systems.

Acceptable safeguards
Equivalent approaches may also qualify.
Transfer Restrictions

Restrictions enforced to limit common ways documents could be moved outside the company. e.g. Through managed devices (Group Policy (GPO), Microsoft Intune, Jamf) or enterprise browser controls (Island, Prisma) Examples include:

  • Block personal email logins (Gmail, Yahoo, etc.)
  • Block personal cloud-storage logins (Box, OneDrive, etc.)
  • Block USB
Watermarking

Downloaded documents contain the company name, logo, or another identifying mark — Aquamark or equivalent. Awareness that documents can be traced back to the company creates a reasonable deterrent to misuse.

Other
Email
When a submission first reaches the inbox —
Once in the system of record, are the submission documents view-only or downloadable?

View-only access meets this requirement. The standard applies to the initial submission package, not routine supplemental documents exchanged later in the funding process.

Downloadable documents need a safeguard to reduce the ability to move them outside company systems.

Acceptable safeguards
Equivalent approaches may also qualify.
Transfer Restrictions

Restrictions enforced to limit common ways documents could be moved outside the company. e.g. Through managed devices (Group Policy (GPO), Microsoft Intune, Jamf) or enterprise browser controls (Island, Prisma) Examples include:

  • Block personal email logins (Gmail, Yahoo, etc.)
  • Block personal cloud-storage logins (Box, OneDrive, etc.)
  • Block USB
Watermarking

Downloaded documents contain the company name, logo, or another identifying mark — Aquamark or equivalent. Awareness that documents can be traced back to the company creates a reasonable deterrent to misuse.

Other

Downloadable documents need a safeguard to reduce the ability to move them outside company systems.

Acceptable safeguards
Equivalent approaches may also qualify.
Transfer Restrictions

Restrictions enforced to limit common ways documents could be moved outside the company. e.g. Through managed devices (Group Policy (GPO), Microsoft Intune, Jamf) or enterprise browser controls (Island, Prisma) Examples include:

  • Block personal email logins (Gmail, Yahoo, etc.)
  • Block personal cloud-storage logins (Box, OneDrive, etc.)
  • Block USB
Watermarking

Downloaded documents contain the company name, logo, or another identifying mark — Aquamark or equivalent. Awareness that documents can be traced back to the company creates a reasonable deterrent to misuse.

Other

2. System Access

We’ll also ask if you have these. Companies are reviewed holistically, and a “No” response does not automatically prevent certification.

Email

MFA enabled for email access.

System of Record

MFA enabled for system of record (CRM or equivalent).

3. Personnel Controls

We’ll also ask if you have these. Companies are reviewed holistically, and a “No” response does not automatically prevent certification.

Background Checks

Background checks are part of your hiring process.

Screen Security

A policy or setting requiring screens to lock when unattended.

Off-Boarding Process

A process for promptly revoking access when personnel leave or change roles.

Final Review

Please allow up to (5) business days for review. We’ll assess your evidence and confirm your business registration is active. If any evidence does not meet the intent of a safeguard, we’ll provide feedback, support, and ample time to address it.