Investor demo · Walk-through portals

Four audiences.
One platform. Click any portal to walk in.

Auth is waived on this preview environment so you can explore each surface without sign-in friction. The same gates apply in production — pilot lenders sign in with email + TOTP step-up; members through .com SSO; investors through the CI portal.

Incorporated

Lunar Flame Sdn Bhd · Co. No. 1361453-X

D&B verified

DUNS 473297787

Data residency

Neon Postgres · Singapore

Identity verification

Innov8tif EMAS · MyKad + ePassport NFC

Audit posture compliant with PDPA 2010 and BNM technology risk-management guidelines. SOC 2 Type II and ISO 27001 readiness tracked publicly on the trust page.

Pick a portal

Admin · Bolehlah team

Operate the platform

The internal control surface — lender onboarding, billing, compliance posture, BYOK keys, BD pipeline, audit, ops.

  • Activations & lender onboarding
  • Billing + Pricing v2/v3
  • Compliance · audit · BYOK
  • BD pipeline + Telegram bot
Walk in
Client · Lender ops

Run a lending book

What a lender sees daily — loan applications, scorecard outcomes, borrower conversations, disbursement, collections.

  • Applications & decisions queue
  • Borrowers + chat history
  • Disbursement settings + rails
  • Billing · usage · invoices
Member · Borrower

Take out a loan

The borrower journey — apply, see credit profile, sign AKAD, manage documents, repay. WhatsApp-first but also full web view.

  • Apply · eligibility · cost disclosure
  • Credit profile + consent layer
  • Documents + AKAD signing
  • Payments + messages
Investor · CI

See what the investor sees

The CI surface — performance, the underlying loan book, distributions, and a B-for-Investors chat across web, WhatsApp, and Telegram.

  • Portfolio overview · NAV · yield
  • Loan-book exposure + concentration risk
  • Distributions · cashflow · statements
  • Compliance posture · consents

This preview runs under a synthetic u_bootstrap_superadmin session for walk-through purposes. The real production gate is tier-2 (password + TOTP) on /admin and /client; tier-1 (.com SSO) on /member. The same gates run on the canonical domains — never bypassed there.

When you're ready to pilot, the gates are real and the audit trail is hash-chained.