Technical FAQ: Security, Privacy, and Performance

How does Modelshop handle Data Privacy and Security?

Security is not an afterthought; it is our foundation. Modelshop is SOC 2 Type II certified and built on a secure, encrypted cloud infrastructure. We employ AES-256 encryption for data at rest and TLS 1.2+ for data in transit.

No. Modelshop acts as an Intelligence Layer, not a secondary data warehouse. We ingest data via secure APIs to perform real-time calculations. Once the decision is rendered and passed to your LOS (Phase 3), the underlying raw transaction data can be purged according to your institution’s specific data retention policies.

Unlike “Black Box” AI, Modelshop is fully transparent. Every logic change is version-controlled. When a regulator asks why a specific decision was made, Modelshop provides a human-readable Audit Log showing the exact version of the model used, the data inputs received, and the specific rules triggered. This ensures 100% compliance with Fair Lending and Adverse Action requirements.

Minimal. Modelshop is designed to be “API-First.” In Phase 1, we work with historical exports (CSV/Excel). In Phases 2 and 3, we connect to your core (Fiserv/Jack Henry) or your data aggregator (Plaid/Finicity) via standard RESTful APIs. This “modular” approach means you don’t have to rewrite a single line of your legacy core code. Integration Hub