Security and compliance

How we protect your borrowers’ files.

The questions your compliance officer and your lenders will ask, answered in plain language. No certificates we do not have, no promises the software does not keep.

Last reviewed [REVIEW_DATE]

Encrypted storage

Every page of the application and the borrower portal is served over HTTPS. A plain web address is sent straight to the secure one, and sign in cookies only travel over secure connections.

Borrower documents are kept in private storage that is encrypted at rest by the storage provider. They never sit in an email inbox or in a folder shared with the outside world.

Encrypted backups, three places

Every night, and again before every software update, the database is copied to three separate places. The two copies that leave the server are encrypted before they go.

One of those copies is locked for 35 days. During that time nobody can change or delete it, not us and not anyone who gets hold of our server, because the server’s own access key does not have permission to delete.

Documents are backed up every night to encrypted offsite storage. If a backup fails, we get an alert by email and WhatsApp.

Restores that are tested

A backup only counts if it comes back. In a restore drill we load the newest offsite backup into a separate, empty database, compare the record counts with the counts saved when the backup was taken, and open a sample of stored documents to confirm they are intact.

We run the drill [RESTORE_FREQUENCY] and keep a record of each one.

Strong sign in

Passwords are stored with scrypt, a one way hash, so they cannot be turned back into the password, not even by us. New passwords need at least 12 characters, and passwords that have appeared in known data breaches are refused.

After 10 wrong passwords, password sign in for that account locks for 15 minutes and the owner gets an email. Sign in attempts from any one network are limited as well. When someone signs in with a password from a browser we have not seen on that account in the last 90 days, the owner gets an email about the new device.

Sessions that expire

Staff are signed out after 30 minutes without activity, and after 12 hours in any case, so an open laptop is never an open file.

Borrowers stay signed in longer so they can come back to finish an upload: up to 7 days without activity and 30 days in total. Signing out, or changing a password, ends the session on our side too.

Sensitive data masked

Social Security numbers and account numbers show only their last four digits, and dates of birth stay hidden. Loan officers see only the loans assigned to them.

Staff who work on a loan can reveal a full number when the file needs it. Each reveal is written to the loan’s history with who did it and when, and the number hides itself again after 30 seconds.

Every action logged

Each loan keeps a timeline of what happened and who did it: when the file was created, every stage change, note and edit, every document received or removed, every reveal of a sensitive number, and every submission to a lender.

Every sign in attempt is recorded with the network address and browser it came from. Company setting changes go to a separate log that cannot be edited afterwards.

Requests checked at the door

Borrower forms, uploads and account changes check that each request comes from our own pages and refuse requests from other sites. Only our own websites may embed the application.

Uploads go through the secure portal. It accepts PDF, JPG, PNG and HEIC files up to 25 MB each, and limits how many files arrive at once.

Where your data lives

[HOSTING DETAILS]

Service providers that handle data for us: [SERVICE PROVIDERS].

How long we keep data

[RETENTION POLICY]

Your Safeguards Rule program

Mortgage brokers and lenders must run an information security program under the FTC Safeguards Rule. LoanProGuru is built to support that program: the controls on this page cover parts of it.

It does not replace your program, your written risk assessment or the qualified individual who oversees it, and using LoanProGuru does not by itself make your company compliant. We hold no security certification today; if that changes, it will be listed here.

Report a problem

If you think you have found a security problem in LoanProGuru, email security@loanproguru.com with what you found and the steps to see it. Please give us a fair chance to fix it before you share it publicly. We confirm every report within [RESPONSE_TIME].

Email security@loanproguru.com

Questions from your compliance officer

Walk through it with us on a live demo.