Security overview

The control areas your review will cover.

Identity & access

Enterprise identity integration and role-based access, so user lifecycle and permissions match your stack.

Open section →

Data protection

Encryption and data-handling practices for borrower PII, the highest-sensitivity data in the lending stack.

Open section →

Audit logging

Every action against a loan record - field updates, overrides, calculations, document changes - is captured with reason and actor.

Open section →

Resilience

Availability and continuity practices for an operation where downtime affects closings in progress.

Open section →

Privacy

Borrower data handled as a first-class engineering and operational concern, not a checkbox.

Open section →

Vendor & subprocessor management

Third parties that process customer data are tracked and disclosed as part of your review.

Open section →
Evidence map

Find the evidence your review requires.

Certifications, attestations, and specific control documentation are shared directly with prospective and current customers under our standard review process - not published generally, so the material you receive is current.

Control areaEvidence
Identity & accessAvailable on request
Data protection & encryptionAvailable on request
Audit loggingAvailable on request
Resilience & availabilityAvailable on request
Privacy & data handlingAvailable on request
Subprocessor listAvailable on request
Request the security packet →
Controls connected to the loan record

Controls built into the workflow, not bolted on.

Permissions, field-level history, override reasons, and document versioning are part of how a loan moves through ReversePilot - not a separate system to reconcile against.

  • Role-based permissions applied at the field level
  • Override reason capture tied to user and timestamp
  • Document version history preserved automatically
  • Audit-bundle export for regulator and investor review
Explore compliance →
Procurement FAQ

Common questions from security and procurement reviews.

What security documentation can you share?

We share our current security package, including control documentation and attestations relevant to your review, directly with prospective customers under our standard process. Request it and we'll route it to the right owner.

How is borrower data handled?

Borrower PII is treated as the highest-sensitivity data in the platform, with access controls and data-handling practices covered in our security documentation. Bring your specific data-handling questions to a security review.

What identity and access options do you support?

Enterprise identity integration and role-based access are available. Bring your specific identity provider and access requirements to a technical review and we'll confirm exact support for your setup.

Can we see your subprocessor list?

Yes - our current subprocessor list is available on request as part of the security packet, and customers are notified before any change.

What is your data retention policy?

Retention is configurable to your regulatory and investor requirements. Specific retention periods are covered in the security documentation available on request.

What is your incident response process?

Our incident response process and notification commitments are detailed in our security documentation and customer agreements - request the packet for the current version.

What availability can we expect?

Availability commitments are addressed in our customer agreements. Bring your specific uptime and continuity requirements to a review and we'll confirm what applies to your contract.

Trust center

Need our security documentation for review?

Request our current security package and we'll route it to the right owner, along with a point of contact for follow-up questions.