Mortgage Intelligence

Security and data

What happens to your documents, stated before you ask.

The question every lender asks second belongs on a page rather than in a contract schedule. Each item below carries its actual status. A thinner truthful page is better than a stronger-looking inaccurate one.

Status labels: Available now Partial In progress Planned Not yet verified


Evaluation data

What an evaluation runs on

MATERIAL
Sample, synthetic, redacted or controlled historical files
Evaluations run on files that do not carry live borrower personal information. This is how serious enterprise evaluations begin in any case: it produces a meaningful measurement quickly and lets you compare findings against outcomes you already know. Available now
LIVE DATA
Use involving live borrower information
Follows completion of the security, privacy and customer-controls program now underway. Ask where it stands and we will say, with dates where we have them. In progress
FORMS
Nothing sensitive through the website
The working-session form asks for a name, a work email and some context. It is not a channel for loan files, and we will not accept borrower documents through it. Available now

Customer documents

Handling, training and the model boundary

TRAINING
Your documents are not training data
Borrower documents processed through the platform, and the findings drawn from them, are not used to train any model: not ours, not the model provider's. Any future mortgage-domain model would use customer data only under a separate, explicit, written agreement you sign knowingly. Available now
PROCESSING
A third-party foundation model reads them
A general-purpose vision-language model from an established provider, running inside our own cloud environment. We say so because implying we built it would be false. We will name the provider under a mutual NDA. Available now
TENANCY
Tenant-scoped access control
The data model is tenant-aware throughout and access is scoped by tenant in application permissions. Enforced end-to-end isolation, tenant administration and cross-tenant negative testing are target, not in place. Partial
RETENTION
Contractual, not a default
Retention periods, deletion on request and destruction at end of term are set in your agreement rather than left to a default. Ask and we will send the current terms before a pilot. Available now

Controls

Identity, audit, encryption and the security program

IDENTITY
Token-based login with session expiry
Roles exist in the data model. Enforced authorization boundaries, role-based administration and single sign-on are target. Partial
AUDIT
Audit events are recorded
Rule executions, reviewer dispositions and material changes produce audit events. Coverage of every action has not been verified end to end, so we do not describe this as complete audit logging. Partial
ENCRYPTION
Encryption in transit and at rest
Managed cloud services with encryption defaults are used throughout. The end-to-end configuration has not been independently verified, so no specific standard is claimed here until it has. Not yet verified
PROGRAM
Security and compliance certification
A current company priority. No certification is held. Alignment work against recognized frameworks is in progress and is not presented as achieved. In progress
OBSERVABILITY
Application-level run metrics
Infrastructure observability, alerting and security detection are target. Partial
RESILIENCE
Managed database and storage services
Defined availability and recovery objectives, with tested backup and restore, are target. Partial

Deployment

Where the platform runs, today and next

TODAY
Vendor-managed cloud environment
The platform runs in our own AWS environment. Loan files delivered for an evaluation are processed there. Available now
NEXT
Deployment inside your own AWS account
We are building a Terraform deployment that stands the platform up in your account, so files and the processing that reads them stay inside your boundary and inherit the network, key management, logging and identity controls you already operate and have had audited. Not available yet. Whether inference also runs inside your account is being decided, and the residency claim will be worded to match. In progress
PRIVATE / ON-PREMISES
Customer-controlled private cloud
On the roadmap behind the customer-account deployment above. Planned

Vendor assessment

We expect one, and we answer in writing

Fannie Mae's Lender Letter LL-2026-04, effective 6 August 2026, and Freddie Mac's Bulletin 2025-16, live since 3 March 2026, require a documented AI/ML governance program and extend that obligation to the AI a lender's vendors use. The GSEs reserve the right to ask why AI is being used, for what purposes, and what safeguards are in place. If you are assessing us as a service provider under either, we expect a written assessment and will answer it in writing.

Subprocessors, as of this page's date: a cloud infrastructure provider and a foundation-model provider, both named under a mutual NDA. This website itself runs no JavaScript, sets no cookies and embeds no analytics; the privacy policy describes what the enquiry form records and for how long. Nothing on this page implies approval, certification or endorsement by Fannie Mae, Freddie Mac or any agency.

Ask us the hard question first.

If the answers above are not satisfactory, a working session is not worth your afternoon. We would rather you asked now.