The products

23 of these are built and 1 are not. Built means the code exists, is tested and runs. It does not mean anybody is using it: none of these has a customer, and nothing here has been run against a real borrower's data. 23 of them can be opened from this page.

Creditcrest Statement

Reads a bank statement. Parses what a bank exports, resolves descriptions past the store numbers and card fragments, finds which amounts recur, and assembles income, commitments, expenses and the facts an assessor should be told — with the transactions behind every figure.

Open it at /statement. Source: src/statement.js, categorise.js, recurring.js, assess.js.

Creditcrest Enrich

Transaction enrichment, as a product of its own. A list of transactions goes in; for each one the category, the third party, and how confident it is and why — with the rule and the words that matched, so a prediction can be checked rather than believed. Categories and third parties are what let you club transactions together, and clubbing them is what turns a list of payments into ongoing commitments and liabilities, which is why the statement reader calls exactly this. Where it does not recognise a payee it says unknown rather than "other", and it reports its coverage by money as well as by row, because one unrecognised two-thousand-dollar payment is a commitment missing from an assessment and forty unrecognised coffees are not.

Open it at /enrich. Source: src/enrich.js, src/categorise.js, models/merchants/au.txt.

Also at /enrich/how-accurate — what it gets right, measured per category and per confidence band against payee lists nobody here chose.

Creditcrest Capacity

The serviceability arithmetic and its inverse. Income shading, the highest-of expense rule, card limits assessed on the limit, a buffered assessment rate, a surplus, the two ratios a credit policy is written in, debt to income against the threshold APRA measures lenders against, and how much could be borrowed on each of those two constraints with the binding one named — every step a line with its inputs and the rule that produced it.

Open it at /statement. Source: src/serviceability.js.

Creditcrest Record

The file a lender keeps. Canonical serialisation, SHA-256, the hash travelling with the content, amendments that append rather than overwrite. It proves the content has not changed since it was sealed. It does not prove the content was true when written, and says so.

Open it at /decisioning/record. Source: src/record.js.

Creditcrest Broker

The best interests duty file. Costs every option the broker considered — interest over a stated window, fees, quantifiable promotions, the offset modelled against a real balance — puts them in order of what they cost, and seals the broker’s recommendation and reasons into one readable file. It refuses to build where ASIC says a reason should be recorded and none is.

Open it at /broker. Source: src/broker.js, src/cdr.js, models/products/au-cdr.js.

Creditcrest Compare

The first thing in this line a person can open. A loan amount, what the property is worth, a repayment type and a term go in; what every lender in the imported Consumer Data Right data publishes for THAT loan comes out, in order of what it costs over the term, with the rate chosen for the loan to value ratio actually entered rather than the lowest one on the sheet. Every row opens onto the band the rate was published for, the rates that ratio does not reach, every fee that went into the figure by name, and the fees that could not be priced and are therefore not in it. Server-rendered HTML with no script, no cookie and no account.

Open it at /. Source: src/compare.js, src/compare-page.js, src/server/*.js.

Also at /back-book — the same data asked a different question: what you pay, against what your own lender publishes today.

Creditcrest Collections

Arrears and financial hardship, as dates rather than as a decision. A hardship notice under s 72 of the National Credit Code starts a statutory clock; this tracks it, says what is due and when with the provision quoted beside every period, reads recent transactions into what the borrower can currently afford, and produces the written-reasons artefact a provider must give when it does not agree to change the contract — sealed through Record, with a person’s name on the conclusion.

Open it at /hardship-clock. Source: src/collections.js, models/hardship/*.txt.

Creditcrest Small Amount

Small and medium amount credit contracts, which are a different regulatory product and not a small mortgage. A small amount credit contract may not charge interest at all: its price is an establishment fee of up to 20% of the adjusted credit amount and a monthly fee of up to 4% of it, so this costs one in dollars and dates rather than as a rate. It tests the protected earnings amount — 10% of available income — against every repayment period separately, because the tightest period decides the contract. It checks the equal-repayment rules in s 133CD, and it reports the presumptions and prescribed circumstances a licensee has to deal with, including the two that were repealed in 2022 and are still widely quoted.

Open it at /small-amount. Source: src/smallamount.js, src/smallamount-surface.js, src/smallamount-page.js.

Creditcrest Apply

The application form as proof that reasonable inquiries were made. A question bank written for each kind of credit, every question tied to the inquiry topic it covers under s 130(1)(a) and (b) — purpose, amount, term, features, income, employment, housing, expenses, other credit and commitments, household, assets, and the changes a bank statement cannot show because they have not happened yet. The lender adds, removes and rewords; a form that leaves a required topic unasked is refused unless a reason is recorded and a second person approves it. Each application becomes a sealed reasonable inquiries record — the words asked, the answers, the form version, and every declared figure beside what the account shows — which Compliance, Decisioning and Intent read.

Open it at /apply. Source: src/apply.js, src/apply-page.js.

Creditcrest Decisioning

A lender’s own credit policy written as rules that can be read, versioned, replayed and defended. The policy is an editable text file a credit risk officer can diff and approve, not code; each version is dated and content-hashed, so a decision made last March can be re-run against the policy as it stood last March and shown to be the same rules. Every rule outcome carries its reason and the figures behind it. It reports which conditions were met and which could not be evaluated. It does not approve and it does not decline.

Open it at /decisioning. Source: src/decisioning.js, models/policies/*.txt.

Creditcrest LoanManager

Origination and servicing, from the application to the account. Before the advance: which product version was on offer on the day and whether an application fits it, the answers checked against the exact form version they were given on and sealed with a hash, the applicant matched to an existing customer or said to conflict, a contact channel proved by a one-time code, a saved application only its owner can open, and the contract’s path from disclosed to signed to funded, refusing to send it before the precontractual statement and information statement (Code s 16) or fund it unsigned. After the advance: a loan replayed from its terms and what happened to it — every payment allocated oldest-due-first; hardship arrangements with a start day, an end day and a fixed payment plan, days past due frozen while one runs and counted on from the frozen figure after it if arrears remain; every account coloured on an arrears scale from green to red; interest accrued daily and summed exactly, an early payout figure that says what it leaves out, and s 31C and s 39B checked as it goes. And the book: the accounts added up on a day — outstanding, arrears by days-past-due band, vintages, collections expected against collected, roll rates between two days, and for a funder a loan tape and a borrowing base on the facility’s own terms.

Open it at /loanmanager. Source: src/servicing.js, src/origination.js, src/loanmanager-surface.js, src/loanmanager-page.js.

Also at /loanmanager/assessment-copy — when a consumer’s copy of their assessment is due under s 132, counted in business days.

Creditcrest Operations

The work a lender’s people do on a file, replayed from what happened: who holds it, a checklist closed item by item with a note of what was seen, documents asked for and received, a figure corrected only with a reason, fields another system read off a document held as a proposal until a person reviews them, service levels in business days with time waiting on the applicant taken out, and a conclusion that stands only once a second person — never the same one — has checked it. The queue puts files past their limit first, then by priority, then oldest.

Open it at /operations. Source: src/operations.js, src/operations-page.js.

Creditcrest Compliance

Whether a lender may switch something on yet, and what shows it. Release gates — licence, legal review, risk approval, tests, security, providers, activation — that fail closed until each is passed, attested by a person on a day, backed by an evidence hash and in date. Live capabilities — intake, contracts, advancing money, collecting it, messages, credit checks, bank data — off until the lender is in production, has switched each on, and has the approvals recorded. A change to a control that stands only when a second person approved it. And obligations traced through controls and tests to current evidence, with every gap named, starting from a register of the provisions this product line already produces evidence for. And the target market: an application checked against the lender’s determination and distribution channels, a review falling due on its period or a trigger, and dealings outside it listed for the issuer.

Open it at /compliance. Source: src/compliance.js, src/operations-page.js.

Creditcrest Portal

What the borrower sees, and what the borrower is sent. The borrower’s own account, built from the lender’s LoanManager ledger so both are looking at one set of figures: what is owed and what is overdue, the next repayment, the payout figure with the Code s 83 sentence, and their rights in plain words — a hardship notice by phone, a payout statement in seven days, copies of the contract and the assessment, the complaints scheme. It will not render without the licensee’s name, licence and complaints scheme. And messages: versioned templates rendered only with every figure supplied and escaped, and a decision on each send in a fixed order — s 133CF first, which forbids offering a small amount contract to anybody who has held or applied for one, then consent, opt-outs, hardship and complaints, frequency and a verified channel — with the reason kept and no quiet switch of channel.

Open it at /portal. Source: src/portal.js, src/portal-page.js.

Creditcrest Growth

Where applications come from and what a funded loan cost, with a lender’s own limits built in. An event taxonomy that refuses personal information, attribution kept to the minimum, a funnel counted in people rather than clicks, cost per funded loan, experiments that may not touch eligibility, serviceability, fees or disclosures and need legal review, reminder journeys that stop after two and the moment an application is submitted, and guardrails that pause growth when a harm measure moves or goes unreported.

Open it at /growth. Source: src/growth.js, src/portal-page.js.

Creditcrest Intent

Intention to pay, read from conduct rather than from arrears alone. It tells a borrower who fell behind through hardship, told the lender and kept a reduced promise apart from one who cancelled the direct debit before the first repayment and went quiet while the assessment showed a surplus. The result is an index from 0 to 100, each signal with its evidence, confidence in a promise to pay, and calibration on the lender’s own book.

Open it at /intent. Source: src/intent.js, src/intent-page.js.

Creditcrest Identity

Who the applicant is, established and recorded. Email and mobile verification codes sent through Resend and SMS with resend limits and lockout and nothing stored on the server; address prefill from the national address file (G-NAF) as the applicant types; ID document, liveness and face match through Didit with the webhook signature checked; and a customer identification record that says what was verified, how, when and by whom, and flags a typed date of birth the document contradicts.

Open it at /identity. Source: src/identity.js, connectors/{resend,sms,didit,gnaf}.js.

Creditcrest AML

A lender’s AML/CTF obligations to AUSTRAC as working software: whether initial customer due diligence is complete and what is missing, a customer risk rating with every factor shown, transaction monitoring over LoanManager ledgers (threshold cash, structuring, third-party repayments, early payouts, refunds to other accounts), suspicious matter reports on the three-day and 24-hour clocks, and the annual compliance report window — each quoted from AUSTRAC’s guidance.

Open it at /aml. Source: src/aml.js.

Creditcrest Payments

Money in and out of a loan book. Direct entry (ABA) files for the lender’s bank, validated field by field before they are written; the day’s debits drawn from LoanManager, skipping accounts in hardship; dishonours turned into ledger reversals, and a stopped payment into the signal Creditcrest Intent reads; PayTo agreements as a state machine; settlement reconciliation; and payouts held until a contract is ready to fund and the account name matches.

Open it at /payments. Source: src/payments.js.

Creditcrest Credit Reporting

Comprehensive credit reporting from the LoanManager ledger: repayment history for each month under the Privacy (Credit Reporting) Code 2025, financial hardship information for months under an arrangement, correction records when a replay changes a month already reported, and a check of every Privacy Act s 6Q condition before a default could be listed — each met, unmet or unknown, with the section beside it.

Open it at /credit-reporting. Source: src/creditreporting.js.

Creditcrest Complaints

Internal dispute resolution under ASIC RG 271. Each complaint is replayed from what happened into its clock: acknowledgement, the 30-day standard response, the 21-day hardship and default-notice responses and their branches, delay notices and closure. A response is checked for real reasons and for the AFCA rights it must state. The register puts overdue files first and names a category as a possible systemic issue, and the half-yearly IDR data report is produced in ASIC’s format.

Open it at /complaints. Source: src/complaints.js.

Creditcrest Privacy

A credit provider’s Privacy Act obligations: access and correction requests under APP 12 and 13 and Part IIIA on their statutory clocks, a register of what personal information is held and for how long, a disposal schedule with legal holds and a sealed disposal certificate, the 30-day eligible data breach assessment, and the automated-decision disclosure APP 1 requires from 10 December 2026.

Open it at /privacy. Source: src/privacy.js.

Creditcrest Documents

Which documents a lender must give, when, and a gate that refuses the next step until each has been given in the version in force that day: credit guide, precontractual statement, small amount warnings, target market determination, key facts sheet on request and the assessment copy. Every version is hashed, and a credit guide missing an item s 126 requires cannot be issued.

Open it at /documents. Source: src/disclosure.js.

Not built

Creditcrest Intake

Taking the transactions by consent under the Consumer Data Right rather than by upload. The engine already does not care where transactions came from, which is why this is an adapter and not a rewrite.

Planned. What is built of it so far: Reading a bank-data provider’s export by a mapping profile that refuses to guess — a changed schema or a duplicated transaction id refuses the whole export — into the transactions the statement reader takes (src/intake.js). Getting the export, by consent, is not built.

Creditcrest Technologies is not a credit provider, is not a credit assistance provider, and does not hold an Australian credit licence. Its software produces evidence; the licensee makes the decision.