Coming soon: Mortgage360 mobile app for iOS & Android — Client portal + Broker portal in your pocket.
Mortgage360
Security

Bank-grade. Audit-grade. Built-in by default.

Every customer data point encrypted at rest and in flight. Every privileged action requires step-up MFA. Every event is signed, immutable, and exportable.

SOC 2
Type II
Audit in progress
AES-256
Encryption at rest
Customer-managed keys
TLS 1.3
In flight
Default everywhere
7 yrs
Audit retention
Immutable
Foundations

The defaults regulators expect

Encryption everywhere

AES-256-GCM at rest. TLS 1.3 in flight. Customer-managed keys (CMK) available on Enterprise tier.

MFA + step-up

TOTP + recovery codes. Step-up required for privileged ops (manual override, AML dismiss, doc unredact).

RBAC (14 × 60+)

14 built-in roles × 60+ permissions. Per-tenant overrides. Admin Force-MFA + Suspend.

Audit log

Every action signed + timestamped + actor-attributed. 7-year retention. Regulator-ready export.

Data residency

Canada / US / EU options. Enterprise can pin per-tenant residency. Right-to-erasure flows.

Infrastructure

Hosted on SOC 2 / ISO 27001 cloud. Multi-region active-active. RPO 5min, RTO 1hr.

Uptime + observability

99.99% target. Public status page. Synthetic monitoring + real-user observability.

Incident response

24/7 on-call. <30min initial response on Sev 1. Public post-mortems for every incident.

Pentest + bug bounty

Annual third-party pentest. Continuous bug bounty via HackerOne. Disclosed in security report.

Audit log

Every action. Forever.

Every login, every doc access, every privileged operation is signed and immutable. Export anytime as JSON, CSV, or regulator-formatted PDF. Hashed chain integrity prevents tampering.
Audit · last 5 events
  • 12:04:11doc.viewufa@msaPatel deal · NOA 2024
  • 12:02:54aml.dismissufa@msaPatel deal · PEP false-positive
  • 11:58:18login.successufa@msaMFA verified · IP 24.x.x.x
  • 11:42:02admin.force_mfaufa@msaTarget: agent@msa
  • 11:24:11policy.updateufa@msaLender list updated
Each row signed with deterministic hash. Chain integrity verified hourly.
Ready when you are

Get the full security overview

Request our security questionnaire response, architecture overview, and current SOC 2 readiness status.

Security — common questions

Is Mortgage360 SOC 2 certified?
Not yet. A SOC 2 Type II audit is in progress and no report has been issued, so we do not claim certification. When the report exists we will say so and make it available under NDA — ask us for the current status and timeline directly.
How is customer data encrypted?
AES-256 at rest and TLS 1.3 in transit, as the default rather than an option. Customer-managed keys are available on the enterprise tier for brokerages whose own obligations require holding the key.
How is access controlled?
Fourteen built-in roles across more than sixty permissions, with per-tenant overrides. Privileged actions — manual overrides, dismissing an AML hit, unredacting a document — require step-up MFA and are recorded against the person who took them.
What does the audit log capture?
Every action, signed, timestamped and attributed to an actor, retained for seven years and exportable in a form a regulator can read. The retention period is set to outlast the record-keeping obligations it exists to satisfy.
Can we run a security questionnaire or a penetration test?
Yes to the questionnaire — request the security package and we will complete yours. Customer-initiated penetration testing is arranged case by case with scope agreed in advance; ask before you schedule anything.
Where is the data hosted?
Ask us and get it in writing for your agreement rather than inferring it from a marketing page. Data residency is a question with a specific, contractual answer, and it is one you should hold us to in the contract.