Legal

FCRA & Permissible Purpose

Last updated: April 26, 2026 · Effective date: April 26, 2026

Customer responsibility notice. iStealth provides software tools that help authorized businesses analyze and process traffic flowing through their own authenticated browser sessions. The legal authority to send any particular request, capture any particular response, or process any particular consumer’s data rests entirely with the Customer, not with FP System LLC. The Customer is responsible for ensuring its use of our tools complies with the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), the Driver’s Privacy Protection Act (DPPA), state-level consumer-protection statutes, and any applicable industry regulations.

1. Scope of this notice

This page describes Customer obligations when using iStealth tools (including the launcher, browser, and the Enterprise-tier iData research module) to interact with services that provide or process consumer-reporting data, financial information, identity-verification scores, or similar regulated data. It is read together with our Terms of Service, Acceptable Use Policy, and Privacy Policy.

This notice is general informational material. It is not legal advice and does not create an attorney-client relationship. Customer must consult qualified counsel for advice on its specific circumstances.

2. What our tools are (and are not)

iStealth’s products are general-purpose B2B software tools. They do not themselves constitute a consumer-reporting agency, do not maintain a consumer-reporting database, and do not furnish consumer reports as defined under 15 U.S.C. § 1681a(d).

When a Customer uses our tools to interact with third-party consumer-reporting agencies or identity-verification vendors (for example LexisNexis, Experian, TransUnion, Trestle, IDDataWeb, MicroBilt, Twilio Identity, Authenticate.com), the legal relationship is between the Customer and that vendor, governed by the Customer’s contract with the vendor and the vendor’s certifications under FCRA. FP System LLC is not a party to that relationship and assumes no responsibility for the Customer’s compliance.

3. Permissible purpose under FCRA

FCRA § 604 (15 U.S.C. § 1681b) restricts when a consumer report may be obtained or used. Common permissible purposes include:

  • Consumer-initiated transaction — the consumer requested a product or service that requires a credit, identity, or fraud check (loan application, account opening, lease, etc.).
  • Review of an existing account — an account the consumer already holds with the Customer, for legitimate business purposes connected to that account.
  • Written instruction of the consumer — the consumer signed a disclosure authorizing the inquiry.
  • Employment purposes with separate consumer authorization (FCRA § 604(b)).
  • Court order or federal grand-jury subpoena.
  • Legitimate business need in connection with a transaction initiated by the consumer.

Customer is responsible for documenting which permissible purpose applies to each inquiry it conducts using iStealth tools, retaining FCRA disclosures and authorizations as required, and providing adverse-action notices to consumers when appropriate.

4. iData research module — specific notes

The iData module (available to Enterprise-tier subscribers) captures, replays, and fuzzes HTTP traffic that originates from the Customer’s authenticated browser session. Because every replayed or fuzzed request is sent from within the Customer’s own session, using credentials issued to the Customer (or that the Customer is otherwise authorized to use), the request inherits the Customer’s legal posture toward the receiving service.

4.1 Pre-conditions for use

The Customer must ensure, before using iData’s replay, auto-fuzz, or direct-query features, that:

  • A documented permissible purpose exists for each consumer whose data is processed.
  • The Customer holds explicit authorization (written agreement, paid subscription, bug-bounty enrollment, or written consent) for each target system being queried.
  • The volume and pattern of inquiries do not exceed what is reasonable for the stated permissible purpose.
  • Banking websites, credit-bureau APIs, and identity-verification vendors typically prohibit automated access in their terms of service. Customer’s usage must respect those terms.

4.2 Technical safeguards we provide

FP System LLC builds technical safeguards into iData to surface these obligations:

  • Authorized-Use confirmation modal before the first Replay or Fuzz operation in each session.
  • Banking-hostname extra-confirmation prompt with the target host spelled out.
  • Per-profile inspector-mode flag so the Customer can keep most browsing sessions outside iData’s scope.
  • Server-side audit log (Section 8 below).

These safeguards are reminders, not legal substitutes. They do not transfer responsibility to FP System LLC.

4.3 Misuse may constitute a federal offense

Misuse of iData against unauthorized systems may constitute violations of the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, banking regulations, FCRA, and other federal and state laws. Customer assumes full liability for its use of iData capabilities.

5. GLBA — financial-information protection

The Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) restricts how non-public personal information held by financial institutions may be obtained and disclosed. When a Customer’s use of iStealth tools touches GLBA-protected data, the Customer is responsible for:

  • Holding the GLBA-permitted relationship that authorizes the access (account servicing, fraud prevention, consumer-initiated transaction, etc.).
  • Maintaining administrative, technical, and physical safeguards (Safeguards Rule, 16 C.F.R. Part 314).
  • Honoring opt-out rights for non-affiliated sharing (Privacy Rule, 16 C.F.R. Part 313).

6. DPPA — driver-record protection

The Driver’s Privacy Protection Act (18 U.S.C. § 2721 et seq.) restricts the disclosure and use of personal information from motor-vehicle records. Customer must hold a permitted-use designation under 18 U.S.C. § 2721(b) for any inquiry that retrieves DMV-derived data.

7. State-law overlay

In addition to federal law, several states impose stricter requirements on Customer use. Notable examples:

  • California: CCPA / CPRA consumer-rights regime, separate from FCRA.
  • Vermont: data-broker registration requirement (9 V.S.A. § 2446 et seq.).
  • New York: SHIELD Act data-security obligations.
  • Illinois: BIPA (biometric information privacy).
  • Texas: identity-theft enforcement act and consumer-data-protection rules.

Customer is responsible for identifying every jurisdiction in which it operates and complying with the applicable state regimes.

8. Audit logs

For Enterprise-tier subscribers, FP System LLC retains server-side audit logs of iData replay, fuzz, and direct-query operations for ninety (90) days. Logs include license key, profile identifier, target hostname, operation type, and timestamp. Logs are retained for incident-response, fraud-prevention, and contractual-compliance purposes.

Customer may request an export of its own audit log at any time during the subscription term. These logs are not, and may not be relied upon as, evidence of the Customer’s permissible purpose — that documentation must be maintained independently by the Customer.

9. Tools we will not provide

FP System LLC will not develop, sell, or operate:

  • Bulk-enumeration tooling that targets consumer-reporting databases without a per-consumer permissible-purpose chain (for example, SSN-range scanning against credit-bureau APIs).
  • Tools designed to bypass a financial institution’s terms-of-service or anti-automation defenses against unauthorized accounts.
  • Identity-fabrication tooling, synthetic-identity generation, or any tool whose primary purpose is the evasion of know-your-customer requirements.
  • Resale or productization of consumer data captured through Customer use of our tools.
  • Custom features that, in our reasonable judgment, would primarily enable unauthorized access or evasion of regulated-data protections.

Requests for any of the above will be declined and may result in termination of the Customer’s subscription, retention of any unused fees, and referral to law-enforcement where appropriate.

10. Shared responsibility model

The line between FP System’s responsibility and the Customer’s responsibility under this notice is summarized as:

10.1 What we are responsible for

  • Delivering software that performs as documented in the Statement of Work and product specification.
  • Securing our infrastructure, license server, and audit-log storage.
  • Providing the technical safeguards described in Section 4.2.
  • Maintaining the audit log and honoring Customer export requests.
  • Disclosing material security incidents that affect Customer data we hold.

10.2 What the Customer is responsible for

  • Holding and documenting permissible purpose for every consumer inquiry.
  • Maintaining the consumer disclosures and authorizations required by law.
  • Holding direct contracts and authorizations with every third-party vendor accessed through iStealth.
  • Operating within the terms of service of every target system.
  • Providing FCRA adverse-action notices when required.
  • Storing and protecting any consumer data the Customer captures using our tools.
  • State-level registrations (data-broker, biometric, etc.) where applicable.
  • Liability for any misuse of our tools by the Customer or its personnel.

11. How to contact us

Questions about Customer compliance obligations should be directed to the Customer’s own counsel.

Questions about iStealth’s tools, audit-log exports, or contractual matters can be directed to [email protected].

© 2026 FP System LLC, Delaware USA. All rights reserved.  · Back to iStealth