Skip to main content

Institutional review

What exactly would we be adopting?

This page is written for the people an institution asks before it adopts anything: risk, security, compliance, audit, and procurement. It states what RunPayway™ governs, where its responsibility stops, what your people control, what can be established later, and what RunPayway™ does not claim to be. Nothing on it requires a conversation with us first.

Financial Fact Verification Infrastructure. RunPayway™ turns scattered financial evidence into one verified account of what a household is committed to, and issues a record of that work. It does not decide what your institution should do about it.

Where our responsibility ends and yours begins.

One line separates the two, and it is the same line in the product, in the record, and in the contract.

What RunPayway™ governs

  • How evidence is registered, read, and attributed to a source
  • Which figures are allowed to carry weight, and on what strength
  • That a disagreement between two documents is surfaced rather than averaged away
  • Which method version was applied, and that a result is reproducible from what was frozen when it was issued
  • That a result is not issued on evidence nobody has resolved

What your institution governs

  • Who works in your organization, what each person may do, and when that ends
  • Which cases are put to RunPayway™ at all, and what evidence is brought to them
  • Every judgment the evidence does not settle by itself
  • Your policy, your thresholds, and what a result means to you
  • The decision, its communication, and its consequences

What RunPayway™ never decides

  • Whether to approve, decline, or price anything
  • Whether a household can afford anything
  • Whether one applicant is a better risk than another
  • What your policy should be, or whether a case meets it
  • Anything an examiner would recognize as a credit decision
Many sourcesEvidenceClaimsConflictsGoverned resolutionVerified financial commitment stateRunPayway™ RecordAuthorized institutional consumers

How a number earns its place in the record.

An institution cannot rely on a figure it cannot place. Five properties decide whether a number reaches a RunPayway™ result at all, and each one is visible afterwards rather than promised beforehand.

Every figure names the document it came from

No amount reaches a result without the stored document it was read out of and the passage within it. A number nobody can place is not a number RunPayway™ will carry.

How that works

For each document on a case the record states separately what RunPayway™ read for itself, what a person asserted, and what a reviewer confirmed against the stored file. Those three are different facts and the record does not let them be read as one, so a scanned statement nothing could open never prints as though the system had evaluated it.

A superseded document stops counting

When a later document replaces an earlier one, the record says which replaced which. It does not show four documents when the result was assembled from two.

How that works

Replacement is recorded once, when the newer source is registered, and travels with the record from then on. Withdrawn and current sources are distinguishable years later without anyone reasoning from filenames and timestamps.

Disagreements are surfaced, never averaged

Where two pieces of evidence contradict each other, the contradiction is carried forward and put to a person. Nothing is blended, and nothing is quietly resolved so the case can keep moving.

How that works

A later document proves that an earlier review is out of date with respect to it. It proves nothing about which figure is right, so arrival order, recency and confidence are not treated as decisions. A person chooses, and they are shown the exact readings they are choosing between — a screen rendered before a third document arrived is refused rather than allowed to settle a question its operator never saw.

Unresolved is a state, not a gap

What is still unresolved stays visible in the record instead of disappearing into a total. RunPayway™ will not issue a result on evidence nobody has settled.

How that works

A refusal is a reportable outcome. It says which material information is missing rather than producing a figure from information the product does not have, which is the difference between a governed result and an estimate.

The record names what the result actually stood on

Reopening a completed record shows the documents whose confirmed values were accepted into it, and the figures each of those documents established.

How that works

That list is captured at the moment the result is issued rather than reassembled later from the live case. It is therefore still correct after the case has moved on — which is the only version of this answer that survives to an audit.

Where automation stops and a person becomes accountable.

Machines prepare. Humans verify. RunPayway™ governs. That is not a slogan about balance; it is an assignment of three responsibilities that the product enforces and does not let anybody trade.

The machine prepares, and claims nothing

Reading documents, computing a payment, amortizing a term, working out remaining monthly margin and stress positions. All of it is arithmetic performed identically every time, and none of it is treated as verified because a machine produced it.

One person records what a document says

An assessor registers a document and records the figures read out of it. That is an assertion about a document, attributed to the person who made it.

A different authority confirms it

Confirming a figure against the stored document is a separate authority from recording it, held by an evidence reviewer. Recording and confirming are two different jobs in the system, not two steps one person is simply trusted to take. Your administrators decide who holds which, and an administrator holds both.

A person is asked only where the evidence does not settle it

Where the evidence answers the question, nobody is asked anything, and no queue accumulates work that does not exist. Two states require a person: a figure nobody independent has verified, and one a reviewer sent back. Nothing becomes work because a day passed or a page was reopened.

Resolving a conflict is preparation, not verification

Deciding between two contradictory readings does not confirm the result. The chosen value returns to the unverified state with no reviewer attached, and an independent reviewer is still the only route to a confirmed figure.

The work takes less of a person's attention without taking any of their authority. Every judgment the evidence does not make for itself is put to somebody in your organization, named, and recorded beside the result.

What your institution controls, without asking us.

Every control below is exercised by your own administrators inside the product. None of it requires a support ticket, a configuration request, or anybody at RunPayway™ touching your organization.

You choose responsibilities, not permissions

An administrator says what a colleague does — prepares cases, confirms evidence, decides who else may work here — and the authority follows from that. There is no permission matrix to maintain and no checkbox that can quietly widen what somebody may do.

Access ends when you end it

An administrator can end a colleague's authority, change what that authority is, or restore it. A departing employee is removed by your own administrator in the product, not by asking somebody with database credentials to do it by hand.

Stopping access is not the same as ending the relationship

Access can be stopped while the institution's decision about what that person may do still stands, and later resumed. Ending authority is a different act: bringing that person back is a fresh decision in which an administrator names the role, because a role somebody held before is evidence about the past and not authorization for the future.

Joining is something you initiate

People reach your organization through an invitation an administrator issues, and which an administrator can cancel or amend. Nobody joins an institution's workspace by signing up.

Your organization is the boundary, not a filter over a shared one

The organization is part of how a record is found rather than a check applied to what was found. Another institution's record does not resolve, so it cannot be read, cannot be acted on, and is indistinguishable from one that never existed.

Your own systems can read your own records

An institution can issue a read-only credential so a system it operates can collect its completed records directly. The credential is not a person, holds no role, can write nothing, and reaches exactly one organization — its own, which is not a parameter any caller can set. An administrator can revoke it.

What you can establish months later, from what was stored.

The RunPayway™ Record is the object an institution keeps. Everything below is answered from stored evidence rather than from anybody's recollection, and none of it depends on the screen it is read on.

Does this result still follow from what it was given?

A completed result can be reproduced from the inputs frozen at the moment it was issued, using the same governed classifier the original ran through. It deliberately does not consult the live case: a source can be withdrawn and a figure re-read afterwards, and a reproduction that read those would answer a much weaker question than the one an auditor is asking.

Which method produced it, and when?

The result, its hash, the method version applied, and the instant the engine issued it stay with the record. Reopening a record does not rerun it.

Who did what to this case, and in what order?

Consequential acts are recorded in one linked sequence, written in the same transaction as the change they describe — so an act that could not be recorded did not happen, and a record of a change that was rolled back cannot survive. Each entry carries who acted, what they acted on, what state it moved from and to, and when.

How do we know that history still says what was recorded?

Your administrators can ask the product to check your institution's recorded history and are told whether it still holds. Findings are scoped to your own records and name no other institution.

What happened across all of our records last quarter?

Record activity is readable across every case at once, and administration history — who was invited, who cancelled it, who changed a role, who removed access, who restored it — is readable separately. Neither is a view of your lending decisions; a completed result is reported as a completed result and as nothing else.

Can we keep a copy outside your product?

A completed record downloads as a single file containing the result, the evidence it stood on, who confirmed what, what was left unresolved, and the audit references that establish the sequence. It is assembled by the same reader that renders the record on screen, so the file you keep and the page your staff read cannot describe the same record differently.

Can we leave without losing the institutional record of what happened?

Yes, and leaving is a governed act rather than an email. Your administrators record your institution's decision to conclude, in your own permanent record; RunPayway™ performs the change that ends workspace access, and refuses to perform it for an institution that has not asked. Nothing is deleted by any of it — not a completed record, not a document, not one audit entry — and a portable record you handed to an auditor still verifies afterwards, because that check never asks whether you are still a customer. Take your copies while your people can still sign in: producing them needs a workspace, and the concluded state stops sign-in for everybody, administrators included. It is reversible, and there is no closed or deleted state for an organization.

Can we hand a record to an auditor who has no account here?

Your institution can produce a portable copy of a record it holds and give it to an examiner, a committee, or a counterparty. They present it back and are told whether it still matches what RunPayway™ recorded when it was produced. Nothing about that route allows anybody to look a record up: it answers only for the artifact in their hands.

That check is a comparison against what RunPayway™ recorded, not a digital signature. It is answered by asking RunPayway™, and it is not verifiable offline against a public key. We state the smaller claim because it is the true one.

The decision boundary

RunPayway™ measures.
The institution decides.

There is no field in a RunPayway™ record that an approval, a decline, an eligibility, a recommendation, a suitability, or an affordability opinion could be written into. The product establishes what the governed evidence supports and issues a record of it. What it means, and what happens next, is your institution's — and the responsibility for it stays there.

  • RunPayway™ is not a lender and originates nothing.
  • RunPayway™ is not an approval engine and issues no decision.
  • RunPayway™ does not underwrite and does not replace an underwriter.
  • RunPayway™ does not rank, score, or compare borrowers against one another.

What you can rely on today, and what you cannot.

RunPayway™ is an early-stage platform. The fastest way through a vendor review is to know both lists before the first call, so both are here.

Available now

  • Governed work performed by your own staff in a web application, with no change to your core or origination system
  • Three responsibilities — administrator, assessor, evidence reviewer — with recording and confirming held apart
  • Administrator control of invitations, roles, suspension, removal, and reinstatement
  • Server-side authorization on every request, from a validated session and a verified membership
  • Per-organization isolation applied when a record is found, not after
  • Evidence provenance: what the machine read, what a person asserted, what a reviewer confirmed, and what superseded what
  • Explicit conflict handling, resolved by a named person and never by recency or averaging
  • Refusal to issue a result on unresolved evidence, reported as what is missing
  • A time-stamped record carrying the result, its hash, and the method version applied
  • Reproduction of a completed result from the inputs frozen at issuance
  • A linked, verifiable history of consequential acts, with an integrity check your administrators can run
  • Record activity and administration history readable across your whole organization
  • Download of a complete governed record as a file you keep
  • A portable copy of a record that a third party with no account can check against what RunPayway™ recorded
  • A read-only credential so a system you operate can collect your own completed records

Not claimed

  • No SOC 2 report, no ISO 27001 certification, and no completed third-party security audit
  • No penetration test result, no compliance certification, and no regulatory approval or endorsement
  • No customer names, logos, testimonials, adoption figures, or uptime statistics
  • No single sign-on: staff sign in with an administrator-provisioned account
  • No core banking or loan origination system connector, and no outbound event delivery
  • No claim about encryption at rest, key management, or a retention and deletion schedule
  • No storage-level immutability: a stored result is protected by the application, not by a database constraint or a write-once store
  • No cryptographic seal and no digital signature: record checking is answered by asking RunPayway™
  • No preserved copy of the screen a record was once displayed on — the stored values are stable, the interface changes
  • No log of who opened or read a record
  • No credit decision, approval, recommendation, affordability opinion, or borrower ranking — not today, and not as a capability this product is working toward
  • No insurance, indemnity, or guarantee of an outcome

None of these is described here as planned, in progress, or coming. If your review requires one of them, raise it in the first conversation and we will tell you what exists and what would have to be built.

Bring your vendor review to the first conversation.

Scope, boundaries, responsibilities, and price are established in writing in the fit conversation. Bring your security questionnaire, your risk requirements, and the absences above. We would rather you learn where RunPayway™ stops in week one than in week six of a pilot.

If your review has reached the question of how you would test this: Institutional evaluation states what an evaluation would put under test, what your institution would bring, what RunPayway™ would do, what you would be left holding, and how you would judge whether it demonstrated anything.

The Financial Proof Network. RunPayway™ establishes a requested financial fact from authorized evidence and issues a proof that can be independently verified.

Prove what matters. Share less.

RunPayway™ provides financial proof infrastructure. It is not financial, legal, tax, or investment advice, and it is not an underwriting or lending decision. A RunPayway™ proof states what was established from authorized evidence. It is not an approval, a guarantee, or a recommendation to proceed, and a result of NOT VERIFIED is not a denial or a judgment about any person. The recipient retains full responsibility for its own decision.