Apply once

How the Afterfirst MCA security setup handles your statements and data

Owners: see how applications and statements are handled today.

This page lists what Afterfirst MCA security covers today: how an application is handled, how bank statements are collected, and the browser protections the site sets. Practices that are not built yet are left off until they are. Afterfirst holds no security certification and makes no claim to one.

By the Afterfirst Editorial Team · Updated

What happens to an application today?

You apply once, and a person on the desk reads each application and replies before any file goes to a funder. The calculators and checkers run in your browser, so nothing typed into them is sent to Afterfirst.

PracticeHow it works today
ApplyingApply once; the apply page lists the fields to include
First replyA person reads the application and writes back before anything is shared
Bank statementsLeft out of the application and sent later, by a method agreed in the reply
Sharing with fundersOnly funders whose programs fit, and only after you have seen our read

How are bank statements collected?

Bank statements are requested only after the desk replies. The reply agrees how they will reach us, so account numbers and owner details do not sit in an ordinary inbox.

How is the site protected in transit and in the browser?

The site build sets standard browser security headers on every page. The headers below are the ones it sets.

Encrypted connections and strict transport

Every page is set to load over HTTPS only. A header tells browsers to refuse plain connections for a year, on subdomains too.

Content restrictions in the browser

A content policy limits scripts, styles and form posts to the site itself. Other sites cannot frame it. The camera, microphone, location and payment features of the browser are off.

Calculators run in your browser

The calculators on the site do their math in your browser. The numbers you type are not sent to Afterfirst.

What the calculators keep

The calculators set no cookies and save nothing in the browser's storage, so closing the page clears what you typed.

How is stored data protected?

Applications sent by email are kept in the desk's email account, and this page makes no other storage claim.

The FTC's guide Protecting Personal Information: A Guide for Business is a plain-language checklist for the same questions of storage, access and disposal.

Who inside Afterfirst can see a file?

Only desk staff working a file see it. Funders see a file only when it fits their buy box and is sent to them.

FAQ

Is applicant data ever sold?

No. Afterfirst does not sell applicant data, and a file is shared only with funders it is submitted to.

Has any auditor certified the setup?

No. Afterfirst has no third-party security certification. This page describes only the practices in place today.

Does the desk keep credit reports?

Ask each funder how any credit review works before you sign, and how it stores what it collects. This page covers only what the desk holds, set out above.

Who sees the details of my existing advances?

Only funders the file is submitted to, since they need them to price a new position. Those details are not shared outside the submissions.

Does a security check add wait time to an application?

No. No security step sits between your application and the desk, so the pace of a file is set by the desk read and the funders.

Can I ask for my data to be deleted, and does it cost anything?

Yes. Write to the desk through the contact page, and there is no charge.

Next step

When you are ready, start the application. We shop your file to funders whose programs fit.

Apply once

Sources

  1. MDN, Strict-Transport-Security header: what the HTTPS-only header under encrypted connections tells a browser to do, including the one-year duration and subdomains.
  2. MDN, Content Security Policy: how the content policy described under content restrictions limits scripts, styles, framing and form posts to the site itself, as this security page says.
  3. FTC, Protecting Personal Information: A Guide for Business: the public checklist named in the stored-data section of this security page.

Send one file.
See what fits.

Start a merchant cash advance application, or write to the desk. Afterfirst MCA is not a lender.

Apply once

Or write to the desk at info@afterfirstmca.com