Built on trust. Protected by design.
Your mortgage involves some of your most sensitive financial information. At Vabasso Mortgage, protecting that information is central to every technology decision we make—from bank-grade encryption and secure cloud infrastructure to rigorous vendor due diligence and continuous monitoring.
Security that meets the expectations of modern financial institutions.
Vabasso Mortgage is built using security practices commonly expected across banking and financial services—modern encryption, secure cloud infrastructure, least-privilege access, multi-factor authentication, continuous monitoring, and tested continuity planning.
Modern TLS standards protect data as it moves between your device and our systems.
Sensitive data is encrypted at rest using industry-standard algorithms.
Hardened, reputable cloud providers operating enterprise-grade data centers.
Access is granted by role, reviewed regularly, and revoked when no longer needed.
People and services receive only the access required for their function.
MFA is required for internal administrative systems.
Logging and monitoring across critical systems help surface anomalies quickly.
Regular, protected backups support recovery from unexpected events.
Documented plans keep essential operations running during disruption.
Recovery procedures are designed and tested to restore service in adverse events.
We carefully choose the companies that help power our platform.
Protecting customer information extends beyond our own systems. Every technology partner undergoes a structured review before becoming part of the Vabasso ecosystem—security, privacy, operational maturity, and regulatory alignment are all evaluated before sensitive information is entrusted to any third party.
- SOC 2 Type II reports, ISO 27001 certification, or comparable frameworks are important considerations within our evaluation process where appropriate.
- Vendors with access to sensitive information are subject to ongoing oversight and periodic re-review.
- Material changes at a partner trigger reassessment.
Your information belongs to you.
We do not sell personal information. Customer information is used only to provide the mortgage services you request, satisfy regulatory obligations, improve your experience, and operate the platform.
- Data minimization: we collect only what we need.
- Purpose-based processing with clear internal ownership.
- Confidentiality, secure storage, and secure transmission across every touchpoint.
We do not sell your personal information—full stop.
Your data is used to help you evaluate mortgage options, submit an application when you choose to, meet legal and regulatory requirements, and improve the service we provide to you.
Security begins long before software reaches production.
Our engineering process treats security as a design input, not a final check. Code review, dependency and patch management, environment separation, and disciplined production controls are the baseline.
Security considerations are woven into design, implementation, and release.
Changes are reviewed by qualified engineers before reaching production.
We track dependencies and apply timely updates for security-relevant issues.
Findings are triaged by severity and remediated on defined timelines.
Production, staging, and development are isolated with distinct controls.
Elevated permissions require justification, approval, and audit logging.
The right people. The right access. Nothing more.
Access to internal systems is protected by multi-factor authentication, strong password policies, session controls, and role-based permissions. Administrative activity is logged.
- 1Verify identity
Multi-factor authentication challenges every administrative sign-in.
- 2Assign least privilege
Roles grant only the access required for a specific responsibility.
- 3Enforce need-to-know
Sensitive operations require additional approval.
- 4Log everything
Administrative activity is captured for auditability.
- 5Review & revoke
Access is periodically re-certified and removed when no longer needed.
Designed with regulated industries in mind.
Our security program is designed to support the expectations of the financial services industry. Internal policies, vendor oversight, employee awareness, and ongoing review reinforce a durable governance posture.
Practices tuned to the realities of mortgage lending.
Documented policies with clear ownership and review cadence.
Ongoing training on privacy, security, and social engineering.
Structured intake and periodic re-review across the vendor portfolio.
Simple habits that protect your financial life.
Even the best-designed platform relies on customers using safe habits. These practices dramatically reduce the risk of fraud and identity theft during a mortgage transaction.
Verify sender addresses, hover before clicking, and be skeptical of urgency.
Use a password manager and unique passwords for financial accounts.
Call our published number to confirm any unexpected request.
Avoid submitting financial documents from public Wi-Fi or shared computers.
Review credit reports regularly and set fraud alerts if warranted.
Contact us immediately at security@vabasso.com if something feels wrong.
Eight principles that guide every security decision.
Security decisions happen before code is written, not after.
We collect what we need, and no more.
Signals from across our stack feed a durable detection posture.
We work with providers whose security posture we can substantiate.
Purpose-based processing, minimal retention, controlled access.
Documented policies, clear ownership, ongoing review.
Encryption in transit and at rest across sensitive systems.
Structured, ongoing review of every partner that touches customer data.
Answers to common security & privacy questions.
Have a question that isn't listed? security@vabasso.com
How is my information protected at Vabasso Mortgage?
Your information is protected using modern encryption for data in transit and at rest, role-based access controls, multi-factor authentication for internal systems, continuous monitoring, and secure cloud infrastructure. Security is built into every layer of our platform.
Do you encrypt my data?
Yes. We use modern TLS standards to encrypt data as it moves between your device and our systems, and industry-standard encryption to protect sensitive data at rest within our infrastructure and with vetted providers.
Do you sell my personal information?
No. Vabasso Mortgage does not sell personal information. Your information is used to provide the mortgage services you request, meet regulatory obligations, and improve your experience.
Who can access my information inside Vabasso Mortgage?
Access is limited on a need-to-know basis using role-based permissions and the principle of least privilege. Only authorized personnel involved in supporting your file may access relevant information, and access is logged.
How are technology vendors selected?
Every prospective technology partner is evaluated across security, privacy, operational maturity, and regulatory alignment. Independent attestations such as SOC 2 Type II or ISO 27001 are important considerations within that review where appropriate.
Do you review vendors on an ongoing basis?
Yes. Vendors with access to sensitive information are subject to ongoing oversight, including periodic re-review, monitoring of material changes, and reassessment when scope, ownership, or risk profile changes.
How is my mortgage application protected?
Applications are transmitted over encrypted connections, stored within access-controlled systems, and processed by authorized personnel and vetted service providers required to originate a mortgage loan.
What happens if a vendor experiences a security incident?
Our vendor process is designed so that incidents affecting a partner are escalated to Vabasso Mortgage, evaluated for customer impact, and, where required, communicated to affected customers in line with applicable law.
Can I request information about my personal data?
Yes. You may contact our team to ask about the personal information we hold about you and how it is used. Where applicable law provides additional rights, we honor those rights.
How do I report suspicious activity or a suspected vulnerability?
Email security@vabasso.com with a clear description. We appreciate responsible disclosure and will acknowledge legitimate reports and coordinate a resolution.
Do you use multi-factor authentication?
Yes. Multi-factor authentication is required for internal administrative systems and is used across our infrastructure and identity providers to reduce the risk of unauthorized access.
Where is my data stored?
Customer data is stored within secure, reputable cloud infrastructure providers that operate hardened data centers with physical, network, and logical security controls.
How long do you retain my information?
We retain information only as long as needed to provide requested services, comply with legal and regulatory obligations, resolve disputes, and enforce our agreements.
Do you use cookies or tracking technologies?
We use limited, purpose-based cookies to operate the site, remember preferences, and understand aggregate usage. Details are described in our privacy and cookie policies.
Is Vabasso Mortgage SOC 2 or ISO 27001 certified?
Our security program is designed to align with the expectations of the financial services industry and to support recognized frameworks. We do not claim certifications we have not obtained; any current attestations will be listed publicly when available.
How do you protect against phishing that impersonates Vabasso Mortgage?
We monitor for brand impersonation, use authenticated email standards, and encourage customers to verify unexpected communications by calling our published number before acting on any request.
What should I do if I receive a suspicious message claiming to be from Vabasso Mortgage?
Do not click links or share information. Forward the message to security@vabasso.com and call us at our published number to verify. When in doubt, assume the message is not legitimate.
Do you support secure document sharing?
Yes. Documents you upload during application move through encrypted channels and are stored within access-controlled systems. Avoid sending sensitive documents by unencrypted email.
How is your production environment separated from testing?
Production, staging, and development environments are separated with distinct access controls, credentials, and data handling rules. Real customer data is not used for testing.
Who do I contact with questions about privacy or security?
Email security@vabasso.com for security matters and privacy@vabasso.com for privacy questions. Our team will respond promptly.
Policies, disclosures & contacts.
The care we bring to your data is the care we bring to your loan.
Whether you're applying for your first mortgage or financing your next investment property, you deserve a lending partner that treats your information with the same diligence as your financial future.