Mortgage Data Security and Access Controls

If you outsource any part of your loan file work, you are trusting a vendor with borrower information. This page explains how BrokerVA approaches that responsibility, and what we can document so you can complete your own vendor review. BrokerVA operates under a GLBA-aligned compliance framework through our NMLS-registered Philippines branch (NMLS #1977844).
What Should You Expect From a Provider on Data Security?
The FTC's Safeguards Rule expects financial institutions, including mortgage brokers, to maintain a written information security program covering things like access controls, encryption, monitoring, and incident response. Brokers remain responsible for borrower data when a vendor handles it, so the right question is not whether a provider says it is secure. It is what the provider can show you.
We've organized this page around five questions that vendor reviews commonly ask. Where we can provide documentation, we will share it on request, so you can judge it against your own requirements.
Read more → Is Offshore Mortgage Processing Compliant?
How Do Specialists Access Borrower Files?
Access should be limited to the people who need it, for the work they are assigned, in the systems agreed for the engagement. At BrokerVA, specialists are directly employed and work with a dedicated HeadVA as your consistent point of contact.
The specific access method, and which of your systems or lender portals a specialist will use, is agreed during setup. We'll confirm it in writing before work begins. Ask us for our description of how access is granted, reviewed, and removed.
Can Files Be Downloaded to a Local Device?
This is a standard due-diligence question, because downloads move borrower information outside the system where it is controlled. We recommend that every client ask any provider, including us, whether local downloads are permitted, and under what conditions. Ask us for our written position on file handling, and compare it to your own policy.
What Access Is Logged and Monitored?
Logging matters because it lets you answer who touched a file and when. A provider should be able to describe what activity is recorded, who reviews it, and how long records are kept. Ask us to describe our logging and monitoring practices, and to confirm which logs you can request for your own files.
Read more → State Examiners Are Now Asking About Your Remote Team's Supervision Policies
What Independent Audits or Certifications Back This Up?
Independent audit reports, such as a SOC 2 Type II report, give a buyer outside evidence. Ask any provider which independent reports it holds, the period they cover, and whether you can see them. We would rather you ask us directly than assume. Request the current status of any independent audit or certification, and we will share what we have documented.
Read more → Not All "Overseas" Is the Same: Licensed Support vs. Unregulated Outsourcing
What Happens If There Is a Suspected Breach?
A provider should have a written incident response process, including who is notified, how fast, and what you will receive. Timelines can also be set by law and by your own agreements. Ask us for our incident response and notification process, and make sure it fits the obligations you carry.
What Can You Request From BrokerVA?
For your vendor review, you can request our security documentation. Tell us what your review requires, and we will share what we have. A useful request covers:
- How access is granted, reviewed, and removed
- Our file-handling and download position
- Logging and monitoring practices
- The status of any independent audits or certifications
- Our incident response and notification process
- Any subcontractors or third parties who may touch your data
Frequently Asked Questions
Where is borrower data stored? That depends on how the engagement is set up and which systems you use. Ask us to confirm in writing where data is stored and accessed, as part of your vendor review.
Do specialists work inside my systems or yours? Which systems are used is agreed during setup. We'll confirm it in writing before work starts.
What documentation can I request? Our description of access controls, file handling, logging, incident response, any independent audit reports, and any subcontractors. Contact us with your review requirements.
Doing a vendor review? Request our security documentation and tell us what you need to see.