Land more loans with ReversePilot · Trust center · Talk to sales · Customer login
Attestations

Operational assurance you can put in front of your auditor.

ReversePilot maintains documented controls, third-party assessments, and security documentation packages your risk and security teams can review directly.

Pen Test
Annual
CAIQ-Lite
Available
ISO 27001
In progress
PCI DSS
SAQ-D · Hosted
NIST 800-53
Mapped
CCPA / CPRA
Aligned
Data protection

Encrypted in transit, at rest, and within the application boundary.

Every byte of borrower PII is encrypted with keys ReversePilot operates — with optional customer-managed keys for enterprise deployments.

Encryption

  • TLS 1.3 minimum for all external traffic
  • AES-256 at rest for database, object storage, and backups
  • Field-level encryption for SSN, DOB, and account numbers
  • Customer-managed keys (CMK) via AWS KMS available on enterprise tier
  • Quarterly key rotation with attestable lineage

Data residency

  • US-only primary data residency by default
  • Single-region or multi-region deployments available
  • Document storage isolated per tenant with object-level ACLs
  • No production data in non-production environments
  • Synthetic data sets for sandbox tenants
Identity & access

Modern identity from the user's first day.

SAML 2.0 SSO, OIDC, SCIM provisioning, and granular role-based access — integrated with the IdP your security team already manages.

SSO

SAML 2.0 and OIDC against Okta, Microsoft Entra, Google Workspace, and Ping. Just-in-time provisioning supported.

SCIM

SCIM 2.0 for automated user lifecycle: provisioning, deprovisioning, group sync, and role assignment from your IdP.

RBAC

Role library covering originator, processor, underwriter, closer, compliance, and executive personas. Custom roles with granular permissions.

MFA

Enforced MFA for all human users, with TOTP, WebAuthn, and IdP-passthrough options.

Session controls

Configurable session lifetime, IP allow-listing, and device trust against your IdP signals.

Service accounts

OAuth2 client credentials for programmatic access, scoped tightly, rotatable, and fully audit-logged.

Audit log

Immutable. Searchable. Exportable.

Every action a user or system takes — field updates, document classifications, calculation runs, integration calls — is captured, stamped, and stored in an append-only log with point-in-time loan reconstruction.

  • Append-only design with hash-chained entries
  • Search by loan, user, action, and time range
  • Export to your SIEM (Splunk, Datadog, Sumo) via streaming or pull
  • 365-day default retention; multi-year tiers for enterprise
  • Every override carries reason, role, and timestamp
{
  "event_id": "evt_01HXC9RZ...",
  "timestamp": "2026-04-22T14:02:11.842Z",
  "actor": { "id": "u_104", "email": "j.albrecht@..." },
  "loan_id": "RP-204881",
  "action": "field.update",
  "field": "max_claim_amount",
  "from": 608400,
  "to": 625500,
  "override": {
    "reason_code": "appraisal_revision",
    "role": "underwriter"
  },
  "hash_prev": "a8c1...e92"
}
Regulatory alignment

Built around the rulebook reverse mortgage lenders live by.

ReversePilot's controls are designed against the specific regulations governing reverse mortgage origination, fulfillment, and post-closing — not retrofitted from forward-mortgage assumptions.

HUD / FHA HECM

Workflow follows HUD HECM origination requirements, including counseling timing, financial assessment, LESA, and FHA insurance application.

NMLS

License-aware originator assignment by state with effective-dating and a designated-state matrix for compliance reviewers.

HMDA

LAR generation with edit checks, data point validation, and submission-ready packaging for the annual filing cycle.

RESPA / TILA

Disclosure timing rules with automatic recalculation and re-disclosure on triggering events.

State seniors

State-specific seniors-protection requirements, including required disclosures and counseling validation flows.

Fair Lending

HMDA-aligned demographic capture and exception reporting suitable for fair-lending program oversight.

Resilience

BCDR you can put in your enterprise risk register.

High availability, regional failover, and continuity exercises designed for an operation where downtime translates directly into delayed closings.

99.99%

Production uptime SLA, measured monthly with public status page.

RTO < 1 hr

Recovery time objective for the production application tier.

RPO < 5 min

Recovery point objective for transactional data via continuous replication.

Annual DR test

Full failover exercise documented in the annual resilience review package.

Privacy

Borrower data handled with the seriousness it deserves.

ReversePilot processes sensitive PII for older Americans — the highest-stakes consumer data in the lending stack. Privacy is treated as a first-class engineering and operational concern, not a checkbox.

  • CCPA / CPRA aligned, including verified consumer requests
  • Per-tenant data isolation with row-level security
  • No use of borrower data for model training
  • Per-record retention controls aligned to investor and regulator
  • DPA available with all customer agreements

Operational practices

  • Background checks on all engineers with production access
  • Least-privilege production access with break-glass workflow
  • Quarterly access review by tenant and role
  • Annual penetration test by independent third party
  • Bug bounty program with public scope
Subprocessors

An itemized, public list — updated when it changes.

We disclose every third party that processes customer data, what they do, and where they operate. Customers are notified before any addition.

SubprocessorPurposeRegionTier
Amazon Web ServicesCompute, storage, networkingUS (multi-region)Core
MailgunTransactional emailUSEmail
StripeSubscription billing onlyUSBilling

Subscribe to subprocessor changes via the Trust Center notification list.

Trust center

Need our security documentation or questionnaire response?

Enterprise prospects can request our current security package, CAIQ-Lite response, and pen test summary under NDA. Existing customers receive updated materials as part of annual reviews.