Connect AI assistants to ReversePilot with our MCP server
ReversePilot's new MCP server lets AI assistants work on your loans as you, with your permissions. Here's what it does and how we kept it safe.
In this article
ReversePilot now has an MCP server, so artificial intelligence (AI) assistants like Claude can look up and work on your reverse mortgage loans. It went live on October 5, 2026. Each assistant works as the person who connected it, with that person's permissions, and it stays off until your company opts in.
This post explains what MCP is, what your loan officers and processors can do with it, and how the server enforces each connected user's existing permissions.
What is an MCP server?
The Model Context Protocol (MCP) is an open standard for connecting AI assistants to the software you already use. An MCP server offers the assistant a short list of tools, such as "find loans" or "list conditions". When you ask a question, the assistant calls those tools and answers from what they return.
This connection lets a supported assistant retrieve current loan information from ReversePilot, so you don't have to copy loan details between windows.
You connect ReversePilot's MCP server to a compatible MCP client using a personal access token.
What your team can do with AI assistants
The server has 14 tools: nine that read loan information and five that make specific, limited changes.
| Read | Change |
|---|---|
| Find loans by borrower name, loan number, Federal Housing Administration (FHA) case number, loan officer, status or address | Add a loan note |
| Your pipeline by status, with the files that have waited longest | Add an underwriting condition |
| Loan summary and status history | Clear a condition or request its review |
| Conditions, fees, quality control (QC) findings and the document list (titles and status only) | Move a loan forward one status, from Prospect up to Underwriting |
| The latest stored loan calculation | Rerun the loan calculation |
A processor planning the morning
"Which of my loans have been in Processing the longest, and what conditions are still open on the top three?" The assistant pulls your pipeline, then the open conditions on each file, and hands you a short work list. It's your pipeline aging review in one question.
A loan officer checking the numbers
"Find the loan on Maple Street, rerun the calculation and tell me the principal limit." The assistant finds the loan and reruns the calculation with the loan's stored product settings, exactly like the Refresh calculations button. It can't recalculate a loan whose calculations are locked or that has reached Clear to Close.
Moving a file along
"Add an internal note that the appraisal came in, then move the loan to Submitted to Underwriting." The note is saved under your name. The status change runs every check the ReversePilot screen runs, including your status-change permissions, required fields and hard stops, and sends the same notifications.
Some things are deliberately left out. The assistant can't delete anything, move a loan to Clear to Close or later, adverse or withdraw a loan, edit fees, borrower or property fields, or open, upload or download documents.
How we kept AI access safe
Compliance and IT teams will ask how this is controlled. We built the server around one rule: it enforces the connected user's permissions on every call, so the assistant can reach only what that user can already reach in ReversePilot.
Off by default
AI access has a platform-wide switch, and it's off for every company until that company opts in. Inside an opted-in company, only Company Administrators and users given the AI access permission can connect. See onboarding your team for how permissions are assigned.
The assistant acts as you, and nothing more
- Same loans. Every tool finds loans through the same list you see in Find Loan. A loan you can't see looks exactly like a loan that doesn't exist.
- Same permissions. Changes need your edit rights on that loan and the same feature permissions the screen checks.
- Your name on it. Every note, condition and status change is recorded as yours.
Super user accounts are refused
ReversePilot Super User accounts can't use AI access at all, by design. Anyone who holds one needs a separate login with normal permissions to connect an assistant.
Personal tokens you control
- Each token belongs to one user, and issuing one requires that user to re-enter their password.
- A token is either read-only or read-write. A read-only token can't change anything.
- Tokens expire after 90 days by default, and never later than one year.
- The token is shown once, and we store only a one-way hash of it.
- A token can be revoked by its owner or by a Company Administrator of the owner's company.
- Tokens are revoked automatically when a user's password changes, the user is deactivated or moves to another company.
Every request also re-checks the user's account, company, permissions and security requirements, so a change takes effect on the next call.
Loan text is data, not instructions
Notes, condition descriptions, document titles and QC findings are typed by people, so they can contain text that reads like a command. The server tells the assistant, in its instructions and in each tool description, to treat that text as data and not to follow instructions found in it.
This is a mitigation against prompt injection, not a guarantee: an AI model can still be misled by text it reads. Narrow tools limit the impact if it is: there is no "edit any field" tool and no delete, and read-only tokens can't change anything.
Limits on the borrower data returned
The tools return only an approved list of structured loan fields. Those lists leave out fields such as Social Security number, date of birth (age is returned instead), borrower phone and email, income, assets, credit scores, bank account numbers, and document contents or download links.
Free text is not redacted. Notes, condition descriptions, document titles and file names are returned as written, and can contain sensitive details someone typed into them. All loan information a tool returns is sent to the connected AI provider, which is why each company decides whether to opt in.
A kill switch and an audit trail
We can switch AI access off for the whole platform or for one company, and revoke every token at once. Every tool call writes an audit log entry recording who called which tool, on which loan, and whether it succeeded.
Status history records when a change came through the AI connection, so you can trace every change back to a person. Rate limits cap how fast any token can read or make changes.
Getting started with the MCP server
Contact ReversePilot to confirm availability and setup for your company. AI access stays off for your company until you opt in, and only users with the AI access permission can connect.
Start with read-only tokens. Enable read-write access only for approved workflows and authorized users, with human review of proposed changes.
Key takeaways
- AI assistants can now find loans, check pipelines, conditions and calculations, and make a few narrow changes in ReversePilot.
- Each assistant acts as the signed-in user, with that user's permissions and loans, and every action is recorded under their name.
- Access is off by default, token-based, revocable at any time, and never available to Super User accounts.
- Returned loan information, including free text, goes to your AI provider.
If you're comparing systems, add AI access controls to your loan origination system (LOS) buyer scorecard, or book a demo to see the AI tools and the controls behind them on a sample file.