Mortgage Clarity processes borrower financial data for advisors at GLBA-regulated lenders. This page covers how we handle that data, the agreements behind it, how we govern AI, and where our compliance program stands today.
TLS 1.2 and 1.3 only, on every connection, with forward secrecy. Qualys SSL Labs graded every production endpoint A+ in August 2026, and the assessment is repeated annually and on any hosting change. Data at rest is encrypted on the database and file storage.
Advisor identity is derived server-side from a verified session token, never from anything the browser sends. Row-level security is enabled on every table as defense in depth behind the application layer, and authorization is enforced at the API, not the interface.
Sessions live in httpOnly, Secure, SameSite cookies, never browser storage. Passwords are screened against known breach corpora at signup and reset, and authentication endpoints are rate limited. MFA for advisors is in active development; SSO (SAML/OIDC) ships with the first enterprise rollout.
A borrower access trail records which advisor viewed which record and when, the log a GLBA examination asks for. Application logs are scrubbed so credentials and borrower details never land in log storage, and borrower NPI is never written to a URL or an analytics event.
Encrypted database backups run daily. The restore path was tested in August 2026 against a production backup, restored into an isolated project and verified in full: measured recovery time under 15 minutes, recovery point up to 24 hours. The test repeats at least annually.
Retention periods are documented per data category and enforced by automated daily jobs. Advisors can export their workspace themselves. Account deletion runs a 30-day cancellable grace period, then a full purge. Borrower records are never aged out unilaterally, because the advisor carries their own retention obligations.
The contractual layer behind the controls: what we sign, what we publish, and what we answer.
Drafted with GLBA Safeguards Rule flow-down, breach notification terms, and subprocessor obligations. It is in legal review and will be offered for countersignature when counsel signs off, because a DPA is a contract, not a policy.
Published terms of service and privacy policy cover data use, RESPA boundaries, and the advisor-client relationship. Borrowers and advisors hold access, export, and deletion rights, honored through self-service export and a deletion path.
The complete subprocessor list is published below and maintained as a controlled document. Customers get 30 days notice before a new subprocessor begins processing their data.
Send a SIG Lite, CAIQ, or your own form and we return it completed, together with the supporting documents from the diligence packet.
This platform uses AI to help produce financial analysis, so the boundary around it is engineered, not aspirational.
Our AI provider does not train on data submitted through its API. Borrower data never becomes training data.
AI drafts an analysis; a licensed advisor edits and approves it. No AI output reaches a borrower unreviewed.
Payments, amortization, breakeven, and closing costs come from a tested calculation engine. The model writes the explanation, never the numbers.
The data inventory records exactly which fields reach a model and which never do. Untrusted document and transcript text is constrained before it reaches a model, and borrower NPI is classified Restricted under our data classification standard.
Adopted August 2026. Any of these is available on request.
An internal security audit in July 2026 covered the full application surface; every Critical, High, and Medium finding was remediated and verified in production. SOC 2 Type I, scoped to the Security and Confidentiality criteria, is funded and in preparation, with the Type II observation window opening once Type I is issued. A third-party penetration test is scoped ahead of the audit, including the share-link and client-portal token surfaces. Card data is fully outsourced to Stripe, which keeps us in PCI SAQ-A scope.
Scoped to Security and Confidentiality criteria.
Observation window opens when Type I is issued.
Controls aligned; access audit trail in production.
Card data is fully outsourced to Stripe.
Mapping produced from SOC 2 evidence.
Pursued only if a specific enterprise agreement requires it.
Sent on request, usually same day.
Not yet issued. Listed so you can plan around it.
Every vendor that touches customer data in production, what it does, and where it processes. Customers get 30 days notice before a new subprocessor begins processing their data.
Database, authentication, and file storage
Advisor and borrower records, documents
Application hosting
Request processing; no independent data store
Edge network, TLS termination, and DDoS protection
All traffic in transit. Reached through our hosting provider rather than a direct contract, and listed anyway because it terminates TLS.
AI analysis drafting and summarization
Scenario details submitted for analysis. Not used for model training.
Subscription billing
Advisor billing details. Card data never reaches our servers.
Transactional email delivery
Recipient name and email address, message content
Sign-in, optional email integration, and web fonts
Advisor identity. Mailbox content only where an advisor connects the integration.
Optional call recording and transcription
Call transcripts, only when an advisor enables it
Product analytics
Product usage events. No borrower financial data.
Property data lookup
Property address only
Title and closing cost quotes
Property address and transaction parameters
Map rendering
Coordinates and addresses
Geographic data
Coordinates and addresses
Scheduling links
Meeting name, email, and time
If you believe you have found a security issue, email us directly. We will acknowledge within one business day, and we will not pursue anyone who reports in good faith.
security@mortgageclarityplatform.comLast reviewed August 2026. This page is maintained against our internal security audit and policy library.
We would rather answer the hard diligence questions early than discover them in month four of a rollout. Send the form you already use, or tell us what your review needs and we will assemble it.