Bank-grade. Audit-grade. Built-in by default.
Every customer data point encrypted at rest and in flight. Every privileged action requires step-up MFA. Every event is signed, immutable, and exportable.
The defaults regulators expect
Encryption everywhere
AES-256-GCM at rest. TLS 1.3 in flight. Customer-managed keys (CMK) available on Enterprise tier.
MFA + step-up
TOTP + recovery codes. Step-up required for privileged ops (manual override, AML dismiss, doc unredact).
RBAC (14 × 60+)
14 built-in roles × 60+ permissions. Per-tenant overrides. Admin Force-MFA + Suspend.
Audit log
Every action signed + timestamped + actor-attributed. 7-year retention. Regulator-ready export.
Data residency
Canada / US / EU options. Enterprise can pin per-tenant residency. Right-to-erasure flows.
Infrastructure
Hosted on SOC 2 / ISO 27001 cloud. Multi-region active-active. RPO 5min, RTO 1hr.
Uptime + observability
99.99% target. Public status page. Synthetic monitoring + real-user observability.
Incident response
24/7 on-call. <30min initial response on Sev 1. Public post-mortems for every incident.
Pentest + bug bounty
Annual third-party pentest. Continuous bug bounty via HackerOne. Disclosed in security report.
Every action. Forever.
- 12:04:11doc.viewufa@msaPatel deal · NOA 2024
- 12:02:54aml.dismissufa@msaPatel deal · PEP false-positive
- 11:58:18login.successufa@msaMFA verified · IP 24.x.x.x
- 11:42:02admin.force_mfaufa@msaTarget: agent@msa
- 11:24:11policy.updateufa@msaLender list updated
Get the full security overview
Request our security questionnaire response, architecture overview, and current SOC 2 readiness status.
Security — common questions
- Is Mortgage360 SOC 2 certified?
- Not yet. A SOC 2 Type II audit is in progress and no report has been issued, so we do not claim certification. When the report exists we will say so and make it available under NDA — ask us for the current status and timeline directly.
- How is customer data encrypted?
- AES-256 at rest and TLS 1.3 in transit, as the default rather than an option. Customer-managed keys are available on the enterprise tier for brokerages whose own obligations require holding the key.
- How is access controlled?
- Fourteen built-in roles across more than sixty permissions, with per-tenant overrides. Privileged actions — manual overrides, dismissing an AML hit, unredacting a document — require step-up MFA and are recorded against the person who took them.
- What does the audit log capture?
- Every action, signed, timestamped and attributed to an actor, retained for seven years and exportable in a form a regulator can read. The retention period is set to outlast the record-keeping obligations it exists to satisfy.
- Can we run a security questionnaire or a penetration test?
- Yes to the questionnaire — request the security package and we will complete yours. Customer-initiated penetration testing is arranged case by case with scope agreed in advance; ask before you schedule anything.
- Where is the data hosted?
- Ask us and get it in writing for your agreement rather than inferring it from a marketing page. Data residency is a question with a specific, contractual answer, and it is one you should hold us to in the contract.