Skip to content

How Loandock handles borrower data

Loandock is an AI loan processor. Clara works your files inside the systems you already run.

These controls come from our written information security policy.

Where borrower data sits

  • Your LOS stays the system of record.
  • Your files are kept apart from every other client's.
  • Borrower documents and messages are encrypted in transit and at rest.
  • The work runs in the United States. No borrower NPI is handled outside the country, and no offshore labor touches a file.
  • Multi-factor authentication on every system that reaches borrower data, your LOS included. Your LOS credentials sit in an encrypted vault, never in plain text.
  • Access is least privilege, tied to a named person, with no shared logins.
  • Live borrower data is never used in development or testing.
  • Documents are opened away from the systems that hold your data and make changes to your file.
  • Written rules govern where borrower information can be read, stored and sent.
  • Every action is logged with a timestamp, who took it, and the loan file it touched. Borrower messages too.

AI providers

AI processing runs in the United States. Providers work under enterprise terms that prohibit training on what we send them, and Loandock does not train on client data. A current provider list is available on request.

Regulatory obligations

  • GLBA and the FTC Safeguards Rule, 16 CFR Part 314.
  • TCPA and applicable state quiet-hours rules on every borrower message.

Outside documents cannot act on your file

Documents and email from outside are read away from the part of the system that sends, writes and pays.

Loandock checks who it is talking to

Approved domains and known contacts are on file, and payoff and wire destinations are checked against what the file already says before anything goes out.

Incident response and deletion

  • We tell you within 72 hours of confirming an incident involving your data.
  • We document root cause and corrective actions within 30 days.
  • On termination we return or destroy your data within 30 days of written request, certified if you ask.
  • Disposal is cryptographic erasure or secure deletion.
  • Everyone with access to borrower data takes security training at onboarding and every year, wire fraud included.

Retention

Borrower documents and loan-file data handled for you

Retention

As long as needed to perform the service and to meet your regulatory retention obligations, or as you direct

Deletion trigger

Your direction, or written request on termination; returned or destroyed within 30 days, certified on request

Action logs and borrower communication logs

Retention

Retained with the loan-file data they belong to, available to you for audit

Deletion trigger

Same trigger as the loan-file data

Backups

Retention

Encrypted and access-controlled like production, disposed by cryptographic erasure or secure deletion

Deletion trigger

Same trigger as the loan-file data

Borrower contact

Clara texts and emails borrowers. Sends respect quiet hours and carry an opt-out. Read the SMS policy and privacy policy.

Processing boundaries

Loandock is not a lender. It does not make credit decisions, price loans, touch your AUS findings, or clear conditions. Clara marks each condition fulfilled. Your underwriter clears it, and lender policy stays authoritative. NMLS 2662424.

For vendor review

Loandock does not have a SOC 2 report. Request the information security policy, the current provider list, or other due-diligence documents at info@loandock.com.

LOS access

What Clara reads and writes, and how you grant and revoke access, is on the LOS integration page.