Security Overview

How LoanBot AI protects information

This page describes LoanBot AI's current security approach and governing requirements. It does not claim that LoanBot AI is SOC 2 certified, ISO certified, or covered by a provider's audit unless a current report expressly includes LoanBot AI and its custom application controls.

Version 1.1Effective August 18, 2026Owner: LoanBot AI Management

1. Security governance

LoanBot AI maintains a written information security program, risk register, incident response process, business continuity and disaster recovery requirements, data-retention rules, vendor oversight, and access-control standards. Controls are represented as operating only when dated evidence supports them.

Material exceptions require management approval, an identified owner, compensating controls, and an expiration date.

2. Hosting and shared responsibility

LoanBot AI is a cloud-hosted application built on Base44's managed cloud platform and uses selected third-party services for functions such as storage, email, payments, AI-assisted features, source documents, and listing data. Platform-level safeguards are provider controls and are evaluated through current contracts and assurance evidence.

LoanBot AI remains responsible for its custom code, user permissions, record-level authorization, integrations, data minimization, security configuration, vendor selection, and operational procedures. A provider's certification is not treated as certification of LoanBot AI's custom application.

3. Access control

  • Users receive unique identities and access is based on role, ownership, assignment, and documented business need.
  • Sensitive backend functions must authenticate the caller, authorize the requested record and action, and return only approved fields.
  • Realtor and partner workflows use limited projections rather than unrestricted borrower records where implemented.
  • Privileged access is reviewed and removed when no longer required.
  • Multi-factor authentication for privileged and PMR-data access must be enforced through an approved identity provider and Base44 SSO. A screen or account flag is not accepted as proof of MFA enforcement, and LoanBot does not represent MFA as operating until the login challenge is tested.

4. NPI collection, use, and data minimization

LoanBot AI collects and creates NPI when an identifiable consumer is associated with contact information, mortgage intent, borrower-provided credit range, income, debt, bankruptcy or military status, property and mortgage amounts, transaction status, internal file notes, communications, or derived eligibility, affordability, and program information. LoanBot maintains an internal inventory that maps those categories to their approved use, system location, authorized role, provider path, safeguard, and retention status.

Separate from the NPI categories needed for the approved service, LoanBot policy prohibits intentional collection or storage of the following high-risk identifiers through forms, imports, free text, uploads, APIs, or support channels:

  • Social Security, taxpayer identification, or ITIN numbers;
  • date of birth;
  • bank account or routing numbers;
  • payment-card numbers, CVV/CVC, or PIN data;
  • government identification numbers or images;
  • consumer passwords, login credentials, or recovery codes;
  • exact consumer credit scores obtained from a credit report.

Borrower-provided credit may be represented only as an approved range. Users must not enter prohibited information even when a field is free-form. The prohibited list does not mean LoanBot collects no NPI; it limits the highest-risk identifiers while all approved consumer mortgage and financial information remains protected as Restricted data.

5. Encryption and credentials

  • Restricted data must use encrypted transport over current TLS.
  • Encryption at rest is validated as a provider control and supported by current provider evidence.
  • Application secrets belong in approved server-side secret storage or environment variables, not source code, browser storage, URLs, analytics, screenshots, or logs.
  • Short-lived, scoped upload authorization is used for approved object-storage flows.
  • Credentials are rotated after suspected exposure, personnel separation, or a material vendor incident.

6. Secure development, monitoring, and vulnerabilities

  • Security-sensitive changes require testing, review, a rollback point, and post-change validation.
  • Authorization and cross-user negative tests are required for privileged service-role workflows.
  • Material vulnerabilities are tracked by severity, owner, target date, remediation, and validation evidence.
  • Security-relevant events include role changes, privileged actions, exports, file access, integration changes, deletion, and incident actions where the platform supports them.
  • Independent application testing is obtained as the data scope and customer requirements require; LoanBot does not represent such testing as complete before a report exists.

7. Vendors, continuity, and recovery

Critical providers are assessed for access, data use, encryption, retention, deletion, incident terms, subprocessors, independent assurance, availability, and recovery. Providers may not receive PMR restricted data until that data flow is approved.

LoanBot maintains business continuity and disaster recovery requirements based on its actual architecture. Recovery objectives are not described as tested until a dated exercise and provider evidence support them.

8. Incident reporting

Suspected security events are escalated under LoanBot's Incident Response Plan. When an event may affect PMR information or service, LoanBot follows a PMR-specific notification procedure, preserves evidence, contains access, assesses impact, and provides notice within the shorter applicable contractual or legal timeframe.

The public summary is available on the Incident Response Commitment page.

9. Retention and deletion

Information is retained only for an approved business, contractual, security, or legal purpose. Contract termination and verified deletion requests include production data, files, approved subprocessors, access revocation, backup-aging treatment, and completion evidence where required.

Additional information appears in the Privacy Notice.

Security questions and incident reports should be submitted through the security contact identified in the applicable LoanBot agreement or through the authenticated LoanBot support channel. Do not include Social Security numbers, dates of birth, financial-account information, passwords, or other prohibited data in a report.