Security, Compliance, and Vendor Due Diligence for Community Banks
This page gives bank teams a starting point for vendor review without publicly distributing gated data-protection or confidential diligence materials.
Request gated diligence materials
Runs on AWS infrastructure, which maintains SOC 2 reports. ChiselGrowth does not claim its own certification. Data-protection terms and non-public diligence materials are shared through an approved request-access workflow.
Bank-review ready
We support bank vendor management, compliance, and security reviewers with scoped diligence materials, clear vendor and data-service context, and a request path for non-public evidence.
Operational safeguards we can discuss in vendor review
Bank-only demo intake designed to avoid customer PII and account data.
AWS-hosted application data (Aurora database, Cognito identity, Lambda application API), with tenant isolation enforced at the application layer.
Cloudflare Pages delivery for the public website, demo viewer, and app entry points.
Human approval remains part of regulated marketing workflows; ChiselGrowth is not a substitute for bank compliance approval.
Core vendors, AI/data services, and public data sources
Core infrastructure vendors
Services that host, secure, route, store, or deliver ChiselGrowth application experiences.
Amazon Web Services
Application compute (Lambda), database (Aurora), identity (Cognito), asset storage (S3), key management (KMS), transactional email (SES), and generative-AI workloads (Bedrock)
Cloudflare
Public website, demo, and application hosting via Cloudflare Pages; DNS and CDN routing
PostHog
Product analytics for the marketing site, demo, and application
AI and data services
Services used by server-side generation, enrichment, search, or image workflows when enabled in the approved runtime environment.
Pexels
Licensed stock imagery for published ad creative
ScrapingBee
Residential-proxy fallback for bank website fetches that are blocked by WAF or bot-protection layers
Public data sources
Public or regulator-published sources consumed to verify institution facts or support diligence. These are not presented as subprocessors solely because ChiselGrowth reads public data from them.
FDIC BankFind API
Public institution verification data for FDIC-insured bank matching and official website signals
NMLS Consumer Access
Public license identifier context where applicable to mortgage-related workflows
DPA, security, and readiness materials
Gated by design
- Runs on AWS infrastructure, which maintains SOC 2 reports.
- DPA: available through the approved sales/vendor review channel.
- Vendor and data-service summary: available on this page for initial review; formal subprocessor status, DPA status, and active-runtime posture are confirmed through vendor review.
- Security questionnaire support: available through the vendor review process for qualified bank diligence teams.
Reviewer coordination
Vendor review requests are routed to the ChiselGrowth team so bank reviewers can receive the right packet for their diligence scope without exposing confidential evidence on the public website.
Human bank review remains central to regulated marketing workflows. ChiselGrowth helps prepare draft materials and review context; it does not replace the bank's compliance approval process.
Return to website →