Security Overview
Effective Date: August 26, 2026
Mortgage Vault Corp., doing business as My Mortgage Vault ("Mortgage Vault," "we," "us," and "our")
mymortgagevault.com · 2810 N. Church St., Unit 558336, Wilmington, DE 19802
This Security Overview describes the safeguards we use to protect the personal information you entrust to Mortgage Vault. Security is an ongoing program, not a one-time project; we tell you what we do today and update this page as we improve.
Our approach
We built Mortgage Vault around a small number of principles:
- Least data. We collect what the Services need and nothing else.
- Least access. Only the people and systems that need access to production data get it, and only for as long as they need it.
- Encrypt everything. Personal information is encrypted in transit and at rest.
- Assume mistakes happen. We log, monitor, and rehearse response so we can find and fix problems quickly.
- Own the vendor relationships. Every provider that touches personal information has a written agreement with security and confidentiality obligations.
Encryption
- In transit. All connections between your browser or app and our Services use HTTPS with TLS 1.2 or higher. We use HTTP Strict Transport Security (HSTS) to prevent downgrade attacks.
- At rest. Personal information stored on our servers is encrypted using industry-standard algorithms (AES-256 or equivalent) provided by our cloud infrastructure.
- Passwords. Passwords are never stored in plain text. They are stored as salted hashes using an industry-standard algorithm.
Account security
- Multi-factor authentication (MFA) is available for all Accounts and required for administrator accounts.
- Session management. Inactive sessions expire automatically. You can sign out of all sessions from Account settings.
- Login alerts. We notify you by email of new sign-ins from unrecognized devices or locations.
- Password recovery. Password resets require access to the email address on your Account.
Access controls
- Least privilege. Access to production systems and data is limited to a small number of authorized personnel who need it to do their job.
- Administrator MFA. All administrator accounts require multi-factor authentication.
- Audit logging. Sign-ins, administrator actions, payment events, and Legacy Vault access events are logged. We do not currently log every read of every stored document. Access logs are retained for 90 days. You may request the access log for your own Account by emailing security@mymortgagevault.com; we will provide the prior 90 days of logs within 30 days of the request.
- Off-boarding. Access is revoked promptly when personnel or contractors leave or change roles.
Data isolation and backup
- Tenant isolation. Each Account's Vault content is logically isolated from every other Account.
- Backups. We maintain regular encrypted backups of production data. Backups are retained on a rolling schedule and purged when superseded.
- Deletion. When you delete Vault content, we remove it from active systems within 30 days and from backups within 90 days, subject to legal-hold obligations.
Infrastructure
- Hosting. The Services are hosted on Amazon Web Services (AWS) in the United States. AWS operates the physical data centers and provides the underlying infrastructure security.
- Segregation. Production, staging, and development environments are separated. Real personal information is not used in staging or development.
- Patching. We monitor for security updates to the software we depend on and apply them on a routine schedule; critical updates are applied on an expedited basis.
Payments
Payment card details are collected by our payment processor (Stripe) directly in your browser or app and never touch our servers in full form. We receive a token, the last four digits of the card, the card brand, the expiration month/year, and the billing ZIP code.
Financial-account connections
When you connect a financial account, our data-connection provider (Plaid) collects your institution credentials directly and delivers only the account data you have authorized. Mortgage Vault never sees or stores your online banking username or password.
Vendor management
Every third-party provider that processes personal information on our behalf is listed on our Subprocessor List and is bound by a written agreement that requires appropriate security and confidentiality protections.
Employees and contractors
- Personnel with access to production data are limited to the founder and named contractors under written confidentiality obligations.
- Personnel with access to production systems complete security training on hire.
- We use single sign-on and MFA for the internal tools that touch personal information.
Incident response
We maintain a written Incident Response Plan that assigns roles, defines severity levels, and specifies containment, investigation, remediation, and notification steps. Incident response is handled by our founder and CTO; we do not currently operate a formal 24/7 on-call rotation. If we become aware of a security incident that affects your personal information, we will investigate promptly, contain and remediate the incident, and notify you and any required authorities without undue delay and in accordance with applicable law.
You can report a suspected security issue to security@mymortgagevault.com. We appreciate reports made in good faith and will not pursue legal action against researchers who follow responsible-disclosure practices, avoid privacy violations, and give us a reasonable opportunity to fix the issue before publishing.
What you can do
Security is a shared responsibility. You can help by:
- using a strong, unique password and turning on multi-factor authentication;
- keeping your email account secure (it can be used to reset your password);
- signing out on shared or public devices;
- reviewing which financial accounts are connected in Account settings; and
- reporting anything suspicious to security@mymortgagevault.com.
Changes to this Overview
We update this Security Overview as our security program evolves. Material changes will be posted here with an updated Effective Date.
Contact us
Mortgage Vault Corp. · Attn: Security · 2810 N. Church St., Unit 558336, Wilmington, DE 19802
Email: security@mymortgagevault.com