Enterprise
Built for the security and IT requirements of institutional lenders.
Multi-tenant isolation, role-based access control, full auditability, AI governance, and integration readiness, designed for regulated lending environments where accountability is not optional.
TLS 1.3 + AES-256
Encryption in transit and at rest
SOC 2 Type II
Audit program in progress
GLBA-aligned
Data handling and privacy controls
Multi-tenant isolation
Complete per-lender data separation
Secure multi-tenant architecture
Complete institutional separation, at every layer.
ANVL is designed from the ground up for multi-institution, multi-dealer deployments. Each lender operates in an isolated tenant environment with its own data partition, configuration, and access controls, sharing platform infrastructure without sharing any data, workflows, or system state with other tenants.
- Full data partition between institutional tenants at the storage and application layer
- Independent workflow configuration, exception thresholds, and alert rules per lender
- Separate dashboard, reporting, and administrative environments per institution
- Tenant-level audit logs that are isolated and accessible only to the owning institution
- Support for multi-region dealer portfolios within a single institutional tenant
Tenant isolation
No shared state. No cross-tenant data access.
Isolation is enforced at every layer of the ANVL stack: data storage, application logic, API access, and AI agent operations. There is no pathway (intentional or accidental) by which one lender's data, workflows, or configurations are accessible to another tenant.
- Row-level and schema-level isolation enforced at the database layer
- API authentication scoped to tenant; cross-tenant requests are rejected by design
- AI agent operations are tenant-scoped: no model inference uses cross-tenant data
- Separate encryption keys per tenant for data-at-rest isolation
- Tenant provisioning and deprovisioning with full data purge capability on contract termination
Role-based access control
The right people see the right data, nothing more.
ANVL's permission model is built around institutional lending roles. Lender administrators define role structures, module access, data scopes, and action permissions, so credit analysts, servicers, collectors, finance staff, and executives each have access appropriate to their function.
- Configurable role definitions with module-level and action-level permission controls
- Data scope restrictions: users can be limited to specific dealer sets, regions, or portfolio segments
- Separation of duties enforcement for consequential actions (approval, default initiation, write-offs)
- Administrator-managed role assignment with change logging
- Support for SSO/SAML integration with institutional identity providers
Workflow governance
Process controls built into the platform, not bolted on.
In regulated lending, the process is as important as the outcome. ANVL's workflow engine enforces approval sequences, review gates, and escalation paths, so the operational record demonstrates not just what happened, but that it happened in the right sequence, by the right people, with the right approvals.
- Configurable multi-step approval workflows for credit decisions and policy exceptions
- Required review gates before consequential workflow transitions (default, write-off, recovery)
- Workflow state machine with complete event history for every record
- Configurable delegation rules when primary reviewers are unavailable
- Workflow configuration changes are versioned and logged for compliance review
Auditability
A complete, tamper-resistant record of everything.
ANVL maintains a comprehensive, append-only audit log across all platform activity: data access, workflow decisions, communications sent, AI agent actions, administrative changes, and user logins. Logs are queryable, exportable, and structured to meet institutional audit and regulatory review requirements.
- Append-only event log for all platform activity: data, workflow, communications, and admin
- Every AI agent action logged with the data signal, rule, and outcome
- User access log with session, action, and data scope for every interaction
- Audit log export in structured format for internal audit, regulatory, and legal review
- Configurable log retention periods aligned to institutional and regulatory requirements
AI permissions and oversight
Agents operate within institutional-defined boundaries.
ANVL's AI agents are not autonomous. Lender administrators define (per agent category) what actions agents may take autonomously, what requires human review before execution, and what is presented as a recommendation only. Every agent action is traceable to the data and rule that produced it.
- Per-agent-category permission controls: autonomous, review-required, or recommendation-only
- Override capability for any agent-initiated action by a user with appropriate authority
- Complete agent action log: what signal triggered the action, what the agent did, when, and who reviewed it
- Agent behavior configurable by lender administrators; no platform vendor change required
- AI actions excluded from consequential decisions unless explicitly enabled by the lender
API and integration readiness
Connect to your existing stack without a migration.
ANVL does not require lenders to replace their existing infrastructure to deploy. A documented REST API, webhook support, and SFTP export capability allow ANVL to connect with existing loan management systems, dealer management platforms, data warehouses, and reporting environments.
- Documented REST API for bidirectional data exchange with LMS, DMS, and internal systems
- Webhook delivery for real-time event push to downstream systems (exceptions, payments, status changes)
- SFTP export for scheduled data delivery to internal data warehouses and reporting tools
- Sandbox environment available for integration testing prior to production cutover
- API access controls with per-key scoping and usage logging
Configurable operating models
The platform adapts to how you lend, not the other way around.
Floorplan lenders operate differently. Line structures, curtailment schedules, audit protocols, approval hierarchies, and exception policies vary by institution, product, and dealer type. ANVL's configuration layer lets lender administrators set operating parameters without platform customization requests.
- Configurable loan product structures: line limits, curtailment schedules, maturity terms, and grace periods
- Exception threshold and alert rule configuration per loan type, dealer tier, and risk category
- Approval workflow configuration: step count, reviewer roles, and delegation rules
- Communication template management for dealer notices, exception alerts, and reporting outputs
- Configuration changes versioned and applied with administrator authorization and audit log entry
Data ownership and portability
Your data is yours, at any point in the relationship.
ANVL does not lock lenders into a proprietary data format or make data extraction contingent on contract renewal. Lenders retain full ownership of all loan, collateral, dealer, and operational data. Full export capability is available on request at any time, and on contract termination, data is delivered in a portable format within a defined timeframe.
- Full portfolio data export available on request: loans, collateral, dealer records, and audit logs
- Structured export format (JSON, CSV) without proprietary encoding or vendor-specific schema
- Data portability commitment: export delivered within a defined SLA on contract termination
- No retroactive access restrictions on historical data during the contract term
- Lender retains rights to all data generated within their tenant environment
Enterprise administration
IT and compliance teams stay in control.
Enterprise deployments require administrative controls that IT and compliance teams trust. ANVL provides a dedicated administration environment for user management, role configuration, integration setup, audit log access, and platform health monitoring, without requiring vendor intervention for routine operational changes.
- Centralized admin console for user provisioning, role assignment, and access review
- Integration management: API key issuance, webhook configuration, and connection monitoring
- Audit log access and export tools for compliance team use without IT intermediary
- Platform health and uptime monitoring with configurable alert routing
- Change management log for all administrative actions taken within the tenant environment
How we deploy
Structured deployment. Dedicated implementation.
Every ANVL institutional deployment begins with a scoping engagement, not a self-serve signup. A dedicated implementation lead owns the process from discovery through go-live.
01
Discovery
Portfolio profile, current stack, integration requirements, and pilot scope defined in a structured engagement.
02
Configuration
Tenant provisioned, workflows configured, roles defined, and integrations connected to LMS/DMS environments.
03
Integration
API and webhook connections established. Data mapping validated. Sandbox testing completed before production.
04
Go-live
Lender team trained, dashboards activated, live monitoring begins. Named support contact assigned from day one.