SecureWebX / Auto finance infrastructure Operated by DotNet Holdings LLC · Sacramento, California

Every application arrives complete, encrypted, and on the record.

SecureWebX is the credit origination platform behind dealerships, auto brokers, and the finance companies that fund them. Capture the application, verify the applicant, structure the deal, route it to the right lender, and keep an evidence-grade record of every step.

Your lenders do not need a seat. They open a coded link, review the file, and post a decision back into the same record.

Submission 7K4M2NP9XQ Approved
09:14:22 Application received Address and mobile number verified in place
09:14:24 Sanctions screening cleared OFAC Specially Designated Nationals, no match
09:14:25 Documents encrypted AES-256-GCM, key reference 4c9f…a17
09:31:08 Sent to 3 lenders Coded links, per-lender document scope
11:02:47 Decision received Approved, stipulations attached
8,700+

Lender records in the shared directory, built from NCUA and FDIC source data

AES-256

GCM envelope encryption on every stored document, keys held in AWS KMS

SHA-256

Hash-chained audit log on every application and every company account

24

Report types in the portal, each one frozen as a snapshot when you run it

What runs on SecureWebX

Three jobs, one file, no re-keying.

A credit application usually crosses four systems before it gets funded, and something is lost at every handoff. SecureWebX holds the whole thing: the intake form the customer fills out, the worksheet the manager builds, the package the lender reads, and the record that outlives the deal.

01

Origination

Application intake and verification

A five-step credit application that carries your store's name, not ours. Every rooftop gets its own link and every salesperson gets their own, so you always know where a deal came from. The form asks only for what that store actually needs, address and mobile number are checked while the applicant is still typing, and a partial application is captured the moment step one is done, which means the customer who wandered off is still a lead you can call back.

Branded apply links Address verification Phone verification Abandoned capture Custom fields
02

Submission

Structure, routing, and lender response

Desk the deal against real numbers, then send it where it will actually book. Lenders receive a coded link rather than an email attachment: they open the file, read your note, pull only the documents you scoped to them, and post a decision back into the same record. Where a lender prefers its own pipe, we connect to it, whether that is a REST endpoint, a SOAP service, an S/MIME message, or PGP-signed SFTP.

Desking worksheets LTV / PTI / DTI Reg Z figures Coded lender shares Stipulation checklists
03

Custody

Evidence, retention, and control

Everything a funding auditor or an examiner would ask about is already written down. Documents are encrypted before they touch disk and read through a watermarked viewer instead of being handed out as files. Every login, every status change, every share and every decision lands in a hash-chained log, so a quietly edited row does not stay quiet. Sanctions screening runs at the moment of submission rather than as a monthly batch.

OFAC screening Watermarked viewer Chained audit log Virus scanning GLBA disclosures
The path a deal takes

From the phone in the customer's hand to the funding file.

01

Capture

The customer opens your link on a phone and works through five short steps. The address is matched against a real postal record and the mobile number is verified while they are still on the form.

02

Screen

Applicant details are checked against the OFAC Specially Designated Nationals list before the file is opened by anyone in the store, and the result is written into the record either way.

03

Desk

A manager structures the deal on a worksheet: price, trade, payoff, cash down, term, rate, back-end products, and the loan-to-value, payment-to-income and debt-to-income figures that follow from them.

04

Submit

Choose your lenders. Each one gets its own coded link, its own message, and only the documents you scoped to it, along with a permanent submission id you can both quote on the phone.

05

Decide

Approvals, counters, and declines post back into the record and move the deal to the next stage on their own. Stipulations arrive as a checklist you can clear, not as a voicemail.

06

Retain

The application, the documents, the correspondence, and the full chain of events stay encrypted, searchable, and exportable for as long as your retention policy requires.

On the lot, not at the desk

There is a real SecureWebX app, on both stores.

Most of this industry still asks a finance manager to walk back to a desktop. We publish native applications for iPhone and Android, signed and reviewed on the App Store and Google Play, so the deal moves while the customer is still standing next to the car.

Free with your account. The same encryption, the same audit trail, the same records.

Send the link from the lane

Text your personal application link to the customer from the phone in your pocket, and watch it come back in.

Approvals as they land

A lender decision reaches you the moment it is posted, wherever you are on the lot.

The file, not a summary

Open the application, the worksheet, the documents and the correspondence in the same secure viewer the desktop uses.

Nothing cached in the clear

Documents stream into the watermarked reader. They are not written to the phone, so a lost handset is not a data breach.

Security posture

A credit application is the most sensitive document in the store.

Name, address, date of birth, social security number, employer, income. It is the exact package identity thieves want and the exact package the Safeguards Rule expects you to protect. We designed for that first and built the convenience on top of it, not the other way around.

Security controls and how they are implemented
ControlImplementation
Data at restAES-256-GCM envelope encryption. Keys are held in AWS KMS and the ciphertext lives in a private bucket, so a stolen file is a stolen blob.
Document accessA view-only watermarked reader. Printing or downloading requires re-authentication and both actions are written to the record.
Sanctions screeningOFAC Specially Designated Nationals check runs at the moment of submission, with the outcome stored against the application.
File safetyEvery upload and every inbound message is scanned by ClamAV before it is stored or shown to anyone.
Audit trailPer-application and per-company logs where each entry is hashed against the one before it. Tampering breaks the chain and shows.
IdentifiersNo database ids appear in a URL. Every record is addressed by an opaque token, so nothing can be enumerated by counting.
Lender accessTime-limited coded links with per-lender document scope. Access can be revoked without touching the underlying file.
TransportTLS everywhere, with PGP or S/MIME layered on top where a lender requires it for SFTP or email delivery.

The finance office is where a good month is made or lost. It should not run on a fax machine, a shared inbox, and a folder of scanned PDFs nobody can account for.

Get started

Tell us how your store or your credit desk works today.

We will walk through your intake, your lender list, and your funding requirements, then show you the platform against your own process rather than a canned demo.

No obligation, and nothing installed at the store. Setup is a conversation, not a project.