Security at mtge.ai
Lenders trust mtge.ai with the guidance their compliance decisions rest on. Security is therefore part of the product, not a layer on top of it: every answer is traceable to a source, every change is logged, and every record of what was said is tamper-evident.
Infrastructure and data protection
mtge.ai runs on SOC 2-audited cloud infrastructure in U.S. regions. Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Each customer's Customer Content and audit records are logically isolated by tenant, and production access requires hardware-backed multi-factor authentication and is limited to named engineers on a need-to-know basis.
Identity and access
Customers authenticate with single sign-on (SAML 2.0 and OIDC) or with password plus multi-factor authentication. Role-based access control lets administrators define who can ask questions, publish sources, approve overlays, or view audit records. Sessions time out on inactivity and are revoked immediately on deprovisioning.
Source integrity and provenance
Every monitored source carries its publisher, version, effective date, and a content hash. Answers cite the exact passage they rest on, and the platform refuses to reach a production answer from a source whose rights or currency are unresolved. This is what makes an answer audit-ready rather than merely plausible.
Append-only audit trail
The audit log records who asked what, which sources were used, what the answer was, and who was notified of a change. Entries are hash-chained and append-only; the database rejects updates and deletes at the trigger level. Reconciliation runs continuously and surfaces any discrepancy to administrators.
AI safeguards
Generated answers are grounded in retrieved source text and returned with citations so reviewers can verify them. Customer Content and user questions are never used to train foundation models. Model outputs are monitored for hallucination and drift, and low-confidence answers are flagged rather than presented as fact.
Operations and resilience
Encrypted backups are taken daily and tested for restore. Recovery objectives are RPO under 24 hours and RTO under 8 hours. Changes to production follow peer review, automated testing, and staged deployment. Dependencies are scanned continuously and critical vulnerabilities are patched within 72 hours.
Compliance program
Our controls are mapped to SOC 2 Trust Services Criteria and to the GLBA Safeguards Rule expectations that regulated lenders pass to their service providers. Independent penetration tests are performed at least annually. Reports, questionnaires, and our sub-processor list are available to customers and prospects under NDA.
Responsible disclosure
We welcome reports from security researchers. Please give us reasonable time to remediate before public disclosure; we will not pursue action against good-faith research that respects customer data.