Bank-grade. Audit-grade. Built-in by default.
Every customer data point encrypted at rest and in flight. Every privileged action requires step-up MFA. Every event is signed, immutable, and exportable.
The defaults regulators expect
Encryption everywhere
AES-256-GCM at rest. TLS 1.3 in flight. Customer-managed keys (CMK) available on Enterprise tier.
MFA + step-up
TOTP + recovery codes. Step-up required for privileged ops (manual override, AML dismiss, doc unredact).
RBAC (14 × 60+)
14 built-in roles × 60+ permissions. Per-tenant overrides. Admin Force-MFA + Suspend.
Audit log
Every action signed + timestamped + actor-attributed. 7-year retention. Regulator-ready export.
Data residency
Hosting location is confirmed in writing for your agreement, not inferred from a marketing page. Ask for it in the security package.
Infrastructure
Hosted on a cloud platform with SOC 2 and ISO 27001 attestations. Backup and recovery details are covered in the security package.
Status page
Not live yet, so we do not link one. Until it is, customers affected by an incident hear about it from us directly.
Incident response
Report security issues to security@mortgage360.ai. Incidents involving your data are notified as your agreement and PIPEDA's breach-reporting rules require.
Vulnerability disclosure
Researchers can report vulnerabilities to security@mortgage360.ai. There is no public bug-bounty programme yet; penetration-testing status is covered in the security package.
Every action. Forever.
- 12:04:11doc.viewufa@msaPatel deal · NOA 2024
- 12:02:54aml.dismissufa@msaPatel deal · PEP false-positive
- 11:58:18login.successufa@msaMFA verified · IP 24.x.x.x
- 11:42:02admin.force_mfaufa@msaTarget: agent@msa
- 11:24:11policy.updateufa@msaLender list updated
Get the full security overview
Request our security questionnaire response, architecture overview, and current SOC 2 readiness status.
Security — common questions
- Is Mortgage360 SOC 2 certified?
- Not yet. A SOC 2 Type II audit is in progress and no report has been issued, so we do not claim certification. When the report exists we will say so and make it available under NDA — ask us for the current status and timeline directly.
- How is customer data encrypted?
- AES-256 at rest and TLS 1.3 in transit, as the default rather than an option. Customer-managed keys are available on the enterprise tier for brokerages whose own obligations require holding the key.
- How is access controlled?
- Fourteen built-in roles across more than sixty permissions, with per-tenant overrides. Privileged actions — manual overrides, dismissing an AML hit, unredacting a document — require step-up MFA and are recorded against the person who took them.
- What does the audit log capture?
- Every action, signed, timestamped and attributed to an actor, retained for seven years and exportable in a form a regulator can read. The retention period is set to outlast the record-keeping obligations it exists to satisfy.
- Can we run a security questionnaire or a penetration test?
- Yes to the questionnaire — request the security package and we will complete yours. Customer-initiated penetration testing is arranged case by case with scope agreed in advance; ask before you schedule anything.
- Where is the data hosted?
- Ask us and get it in writing for your agreement rather than inferring it from a marketing page. Data residency is a question with a specific, contractual answer, and it is one you should hold us to in the contract.