Skip to content
Coming soon: iOS & Android apps.Join waitlist
Mortgage360
Security

Bank-grade. Audit-grade. Built-in by default.

Every customer data point encrypted at rest and in flight. Every privileged action requires step-up MFA. Every event is signed, immutable, and exportable.

SOC 2
Type II
Audit in progress
AES-256
Encryption at rest
Customer-managed keys
TLS 1.3
In flight
Default everywhere
7 yrs
Audit retention
Immutable
Foundations

The defaults regulators expect

Encryption everywhere

AES-256-GCM at rest. TLS 1.3 in flight. Customer-managed keys (CMK) available on Enterprise tier.

MFA + step-up

TOTP + recovery codes. Step-up required for privileged ops (manual override, AML dismiss, doc unredact).

RBAC (14 × 60+)

14 built-in roles × 60+ permissions. Per-tenant overrides. Admin Force-MFA + Suspend.

Audit log

Every action signed + timestamped + actor-attributed. 7-year retention. Regulator-ready export.

Data residency

Hosting location is confirmed in writing for your agreement, not inferred from a marketing page. Ask for it in the security package.

Infrastructure

Hosted on a cloud platform with SOC 2 and ISO 27001 attestations. Backup and recovery details are covered in the security package.

Status page

Not live yet, so we do not link one. Until it is, customers affected by an incident hear about it from us directly.

Incident response

Report security issues to security@mortgage360.ai. Incidents involving your data are notified as your agreement and PIPEDA's breach-reporting rules require.

Vulnerability disclosure

Researchers can report vulnerabilities to security@mortgage360.ai. There is no public bug-bounty programme yet; penetration-testing status is covered in the security package.

Audit log

Every action. Forever.

Every login, every doc access, every privileged operation is signed and immutable. Export anytime as JSON, CSV, or regulator-formatted PDF. Hashed chain integrity prevents tampering.
Audit · last 5 events
  • 12:04:11doc.viewufa@msaPatel deal · NOA 2024
  • 12:02:54aml.dismissufa@msaPatel deal · PEP false-positive
  • 11:58:18login.successufa@msaMFA verified · IP 24.x.x.x
  • 11:42:02admin.force_mfaufa@msaTarget: agent@msa
  • 11:24:11policy.updateufa@msaLender list updated
Each row signed with deterministic hash. Chain integrity verified hourly.
Ready when you are

Get the full security overview

Request our security questionnaire response, architecture overview, and current SOC 2 readiness status.

Security — common questions

Is Mortgage360 SOC 2 certified?
Not yet. A SOC 2 Type II audit is in progress and no report has been issued, so we do not claim certification. When the report exists we will say so and make it available under NDA — ask us for the current status and timeline directly.
How is customer data encrypted?
AES-256 at rest and TLS 1.3 in transit, as the default rather than an option. Customer-managed keys are available on the enterprise tier for brokerages whose own obligations require holding the key.
How is access controlled?
Fourteen built-in roles across more than sixty permissions, with per-tenant overrides. Privileged actions — manual overrides, dismissing an AML hit, unredacting a document — require step-up MFA and are recorded against the person who took them.
What does the audit log capture?
Every action, signed, timestamped and attributed to an actor, retained for seven years and exportable in a form a regulator can read. The retention period is set to outlast the record-keeping obligations it exists to satisfy.
Can we run a security questionnaire or a penetration test?
Yes to the questionnaire — request the security package and we will complete yours. Customer-initiated penetration testing is arranged case by case with scope agreed in advance; ask before you schedule anything.
Where is the data hosted?
Ask us and get it in writing for your agreement rather than inferring it from a marketing page. Data residency is a question with a specific, contractual answer, and it is one you should hold us to in the contract.