---
title: Security & compliance | Mortgage Clarity trust center
description: How Mortgage Clarity handles borrower data: encryption, tenant isolation, access logging, GLBA posture, AI governance and the no-training commitment, published subprocessors, and an honest live / building / planned status on every compliance claim.
url: https://www.mortgageclarityplatform.com/security
site: Mortgage Clarity
updated: 2026-09-01
---

# Security at Mortgage Clarity

Mortgage Clarity processes borrower financial data for advisors at GLBA-regulated lenders. This page covers how we handle that data, the agreements behind it, how we govern AI, and where our compliance program stands today.

Request the diligence packet[Compliance status](#compliance)

## How we handle your data

### Encryption

TLS 1.2 and 1.3 only, on every connection, with forward secrecy. Qualys SSL Labs graded every production endpoint A+ in August 2026, and the assessment is repeated annually and on any hosting change. Data at rest is encrypted on the database and file storage.

### Tenant isolation

Advisor identity is derived server-side from a verified session token, never from anything the browser sends. Row-level security is enabled on every table as defense in depth behind the application layer, and authorization is enforced at the API, not the interface.

### Account protection

Sessions live in httpOnly, Secure, SameSite cookies, never browser storage. Passwords are screened against known breach corpora at signup and reset, and authentication endpoints are rate limited. MFA for advisors is in active development; SSO (SAML/OIDC) ships with the first enterprise rollout.

### Access logging

A borrower access trail records which advisor viewed which record and when, the log a GLBA examination asks for. Application logs are scrubbed so credentials and borrower details never land in log storage, and borrower NPI is never written to a URL or an analytics event.

### Backups & recovery

Encrypted database backups run daily. The restore path was tested in August 2026 against a production backup, restored into an isolated project and verified in full: measured recovery time under 15 minutes, recovery point up to 24 hours. The test repeats at least annually.

### Retention & deletion

Retention periods are documented per data category and enforced by automated daily jobs. Advisors can export their workspace themselves. Account deletion runs a 30-day cancellable grace period, then a full purge. Borrower records are never aged out unilaterally, because the advisor carries their own retention obligations.

## Agreements

The contractual layer behind the controls: what we sign, what we publish, and what we answer.

### Data processing agreement

Drafted with GLBA Safeguards Rule flow-down, breach notification terms, and subprocessor obligations. It is in legal review and will be offered for countersignature when counsel signs off, because a DPA is a contract, not a policy.

### Terms & privacy

Published terms of service and privacy policy cover data use, RESPA boundaries, and the advisor-client relationship. Borrowers and advisors hold access, export, and deletion rights, honored through self-service export and a deletion path.

[Privacy Policy](https://www.mortgageclarityplatform.com/privacy)[Terms of Service](https://www.mortgageclarityplatform.com/terms)

### Subprocessor notice

The complete subprocessor list is published below and maintained as a controlled document. Customers get 30 days notice before a new subprocessor begins processing their data.

### Vendor questionnaires

Send a SIG Lite, CAIQ, or your own form and we return it completed, together with the supporting documents from the diligence packet.

## Data & AI governance

This platform uses AI to help produce financial analysis, so the boundary around it is engineered, not aspirational.

### No training on customer data

Our AI provider does not train on data submitted through its API. Borrower data never becomes training data.

### A licensed advisor approves every output

AI drafts an analysis; a licensed advisor edits and approves it. No AI output reaches a borrower unreviewed.

### Deterministic math, not generated math

Payments, amortization, breakeven, and closing costs come from a tested calculation engine. The model writes the explanation, never the numbers.

### A documented AI boundary

The data inventory records exactly which fields reach a model and which never do. Untrusted document and transcript text is constrained before it reaches a model, and borrower NPI is classified Restricted under our data classification standard.

## Policies

Adopted August 2026. Any of these is available on request.

-   Information security (WISP)
-   Incident response & breach notification
-   Access control
-   Data classification
-   Data retention & deletion
-   Data inventory & flow map
-   Subprocessor management
-   Vulnerability management
-   Logging & monitoring
-   Encryption & key management
-   Secure development (SDLC)
-   Acceptable use
-   Security training
-   Individual rights

## Compliance

An internal security audit in July 2026 covered the full application surface; every Critical, High, and Medium finding was remediated and verified in production. SOC 2 Type I, scoped to the Security and Confidentiality criteria, is funded and in preparation, with the Type II observation window opening once Type I is issued. A third-party penetration test is scoped ahead of the audit, including the share-link and client-portal token surfaces. Card data is fully outsourced to Stripe, which keeps us in PCI SAQ-A scope.

SOC 2 Type IPlanned

Scoped to Security and Confidentiality criteria.

SOC 2 Type IIPlanned

Observation window opens when Type I is issued.

GLBA Safeguards RuleLive

Controls aligned; access audit trail in production.

PCI DSS SAQ-ALive

Card data is fully outsourced to Stripe.

NIST CSFPlanned

Mapping produced from SOC 2 evidence.

ISO/IEC 27001Planned

Pursued only if a specific enterprise agreement requires it.

### Available today

Sent on request, usually same day.

-   Security overview and control summary
-   Information security policy (WISP)
-   Incident response and breach notification procedure
-   Access control, encryption, and logging standards
-   Data classification, retention, and deletion policies
-   Data inventory and data-flow map, including the AI boundary
-   Vulnerability management and secure SDLC procedures
-   Subprocessor list
-   Privacy policy and terms of service
-   Architecture and data-flow description
-   Internal security audit summary (July 2026)
-   Certificate of good standing (Delaware)
-   W-9 and organizational structure

Request the diligence packet

### Follows the audit

Not yet issued. Listed so you can plan around it.

-   Completed SIG Lite / CAIQ questionnaire
-   Data processing agreement (DPA)
-   Penetration test attestation letter
-   SOC 2 report, once issued
-   Certificate of insurance
-   Business continuity and DR test results

## Subprocessors

Every vendor that touches customer data in production, what it does, and where it processes. Customers get 30 days notice before a new subprocessor begins processing their data.

![](https://www.google.com/s2/favicons?domain=supabase.com&sz=64)

Supabase

United States

Database, authentication, and file storage

Advisor and borrower records, documents

![](https://www.google.com/s2/favicons?domain=render.com&sz=64)

Render

United States

Application hosting

Request processing; no independent data store

![](https://www.google.com/s2/favicons?domain=cloudflare.com&sz=64)

Cloudflare

United States

Edge network, TLS termination, and DDoS protection

All traffic in transit. Reached through our hosting provider rather than a direct contract, and listed anyway because it terminates TLS.

![](https://www.google.com/s2/favicons?domain=anthropic.com&sz=64)

Anthropic

United States

AI analysis drafting and summarization

Scenario details submitted for analysis. Not used for model training.

![](https://www.google.com/s2/favicons?domain=stripe.com&sz=64)

Stripe

United States

Subscription billing

Advisor billing details. Card data never reaches our servers.

![](https://www.google.com/s2/favicons?domain=resend.com&sz=64)

Resend

United States

Transactional email delivery

Recipient name and email address, message content

![](https://www.google.com/s2/favicons?domain=google.com&sz=64)

Google

United States

Sign-in, optional email integration, and web fonts

Advisor identity. Mailbox content only where an advisor connects the integration.

![](https://www.google.com/s2/favicons?domain=fathom.video&sz=64)

Fathom

United States

Optional call recording and transcription

Call transcripts, only when an advisor enables it

![](https://www.google.com/s2/favicons?domain=posthog.com&sz=64)

PostHog

United States

Product analytics

Product usage events. No borrower financial data.

![](https://www.google.com/s2/favicons?domain=rentcast.io&sz=64)

RentCast

United States

Property data lookup

Property address only

![](https://www.google.com/s2/favicons?domain=titlecapture.com&sz=64)

TitleCapture

United States

Title and closing cost quotes

Property address and transaction parameters

![](https://www.google.com/s2/favicons?domain=mapbox.com&sz=64)

Mapbox

United States

Map rendering

Coordinates and addresses

![](https://www.google.com/s2/favicons?domain=esri.com&sz=64)

Esri / ArcGIS

United States

Geographic data

Coordinates and addresses

![](https://www.google.com/s2/favicons?domain=cal.com&sz=64)

Cal.com

United States

Scheduling links

Meeting name, email, and time

### Report a vulnerability

If you believe you have found a security issue, email us directly. We will acknowledge within one business day, and we will not pursue anyone who reports in good faith.

[security@mortgageclarityplatform.com](mailto:security@mortgageclarityplatform.com)

### Related

-   [Privacy Policy](https://www.mortgageclarityplatform.com/privacy)
-   [Terms of Service](https://www.mortgageclarityplatform.com/terms)
-   [For lenders & banks](https://www.mortgageclarityplatform.com/solutions/lenders-and-banks)

Last reviewed August 2026. This page is maintained against our internal security audit and policy library.

## Bring us your questionnaire.

We would rather answer the hard diligence questions early than discover them in month four of a rollout. Send the form you already use, or tell us what your review needs and we will assemble it.

[Send your questionnaire](mailto:security@mortgageclarityplatform.com?subject=Security%20questionnaire%20-%20Mortgage%20Clarity)Request the diligence packet
