# Lightwell ## What is Lightwell? Lightwell is a specialty finance and private credit platform that provides data-driven capital stack management and portfolio data automation for non-bank lenders and private credit originators. It streamlines the process of sourcing, evaluating, and securing capital facilities — including warehouse lines, credit facilities, and institutional capital — for lenders operating across bridge, construction, private money, commercial, NPL, and other specialty finance asset classes. ## Who is it for? - **Specialty finance and private credit lenders** seeking capital facilities matched to their portfolio characteristics and origination volume - **Bridge and construction lenders** managing complex collateral and capital stack structures - **Non-bank originators** with NPL tapes, shadow pipelines, and active loan portfolios seeking institutional buyers or facility providers - **Lender executives and capital markets teams** automating portfolio reporting, stratification, and capital outreach ## Key Features - **Capital matching** — Intelligent matching between lenders and capital providers based on loan type, portfolio size, asset classes, geography, and facility eligibility criteria - **Capital stack management** — Tools for managing layered capital structures including senior debt, mezzanine, and equity components - **Pipeline and opportunity tracking** — Structured intake for loan applications, NPL tapes, and shadow pipeline opportunities across configurable workflow stages - **Lender profiling and outreach** — Structured intake process to capture portfolio characteristics (volume, LTV, asset classes, states) and coordinate lender outreach with owner-approval workflow - **Regulus Engine (AI gap analysis)** — Automated loan tape parsing, collateral normalization, stratification table generation, and gap analysis that identifies missing fields and data quality issues before a bank package is submitted - **Document management** — Standardized tape uploads, executive summaries, stratification tables, and R2-backed secure file storage with signed 7-day access URLs - **Lender portal** — Authenticated portal for reviewing matched capital sources and managing mandate preferences - **Owner dashboard** — Administrative interface for managing lender profiles, contacts, organizations, pipeline opportunities, and coordinating capital matches ## Security Posture & Data Handling Lightwell is designed as a closed, authenticated platform with strict data boundaries. **Authentication:** All lender-facing routes are protected by Supabase Auth (JWT Bearer tokens with JWKS verification). Administrative routes require additional owner-email verification via a dedicated middleware layer. No unauthenticated access to lender data or portfolio information is possible. **Data handling:** Loan tape files and portfolio data are processed in-memory during analysis (Regulus Engine) and are not persisted to relational storage in raw form. Generated reports and standardized tapes are stored in Cloudflare R2 with time-limited signed URLs (7-day expiry). Raw PII fields in loan tapes (borrower names, property addresses) pass through the analysis pipeline and appear in output tapes but are not indexed or stored in a searchable database column. **Encryption:** Datasource credentials and integration passwords are encrypted at rest using AES-256-GCM before database storage. The encryption key is environment-isolated and never logged or transmitted. **Compliance taxonomy:** The platform is designed with GLBA (Gramm-Leach-Bliley Act) and CCPA data handling principles in mind. Portfolio data submitted by lenders is used solely for capital matching and analysis. No lender portfolio data is shared with third parties or used for model training. **Rate limiting:** All API endpoints are rate-limited (200 req/IP/15 min global backstop; tighter limits on AI-powered and file-upload endpoints). Public-facing procedures have Zod-enforced input bounds. Body payload size is capped at 10 MB globally, 50 MB for file uploads only. **Infrastructure:** Deployed on Fly.io (US region) with Supabase PostgreSQL (managed, encrypted at rest). File storage on Cloudflare R2. No third-party analytics or tracking pixels on authenticated pages. ## Contact & URLs - **Application**: https://lightwellfinancial.com - **Platform**: Specialty finance and private credit capital marketplace