Skip to main content

Legal · Mortgage 360 View

Security

This page is maintained by Mortgage 360 View to answer common security and privacy questions about Mortgage 360 View. It describes controls we operate today. It is not a certification, an audit report or a guarantee.

Effective
August 2, 2026
Last updated
August 2, 2026
Version
1.0

The strongest control is not collecting the data

  • No Social Security numbers are collected anywhere on the platform.
  • No credit-report access and no credit-bureau integration.
  • No bank-login credentials and no account aggregation.
  • No storage of full payment-card data; any future payments go directly to a PCI-compliant processor.
  • No precise geolocation collection.
  • Document upload is not enabled. If it is enabled later, retention limits, deletion controls and access logging will ship with it.
  • Calculator assumptions stay in your browser's local storage rather than on our servers.

Controls in place

  • HTTPS/TLS encryption in transit for all pages and requests
  • Managed hosting on Lovable Cloud, with platform-level patching and network protection
  • Least-privilege access to any administrative surface, with multi-factor authentication required for administrator roles
  • Audit logging of material administrative actions, including legal-policy changes and rate approvals
  • Row-level access rules on any stored records, so a user can only reach their own
  • Secrets held in managed secret storage, never in client code or the repository
  • Input validation on server endpoints and signature verification on any inbound webhook
  • Change review before deployment, with a launch gate that blocks release when required legal configuration is missing

Shared responsibility

Our hosting platform is responsible for infrastructure security, patching and physical controls. We are responsible for application configuration, access control, data minimisation and how we handle what you send us. You are responsible for the accuracy of what you enter, for keeping your own device and email secure, and for not sending us sensitive identifiers we do not ask for.

Incident response

Suspected incidents are triaged on receipt, contained, investigated and documented. Where an incident affects personal information, we notify affected individuals and regulators as required by applicable state breach-notification law and within the deadlines those laws set, describing what happened, what data was involved and what steps to take.

Responsible disclosure

Email our contact page with steps to reproduce. Please do not access other people's data, degrade the service or run destructive tests. We will acknowledge your report, keep you updated and credit you if you would like that. We do not claim perfect security and we do not claim any certification.

Contact

Report a vulnerability or suspected incident: our contact page.

All contact details

Designed with compliance controls. This page is maintained by the platform operator and is not a certification, an audit result or legal advice.