Data privacy and security.
How Ad Astra handles borrower data, who can access it and what happens if you ever want to leave. Written for the person who has to sign off on this, not just the person who wants the demo.
Where borrower data sits and who can reach it.
Every question your compliance review will ask, answered before you have to send the email.
It stays in your systems
Borrower data lives in your CRM, your loan origination system and your document storage. We build inside those systems rather than moving your file room somewhere else.
Named accounts, minimum permissions
Access is issued by you, scoped to what the build requires, tied to named accounts rather than shared logins and revocable by you at any time without breaking what is already running.
Read, extract, write, discard
Documents are read to extract fields and confirm completeness. The extracted values are written into your systems. Borrower documents are not retained after processing and are not used to train anything.
No lock-in on your own operation
If you stop working with us, access is revoked, credentials are rotated and the workflows stay where they were built. You are not renting your own pipeline back from a vendor.
What actually happens to a document.
Not a diagram. The literal sequence, in order, for a single file.
A borrower uploads a pay stub, a bank statement, a W-2, into your existing portal or inbox. Nothing is rerouted through a separate system first.
It is read to extract the specific fields your workflow needs and to confirm the file is complete against what the lender requires.
The output goes into your CRM or your LOS, the systems that were already your system of record before this was built.
The document is not copied into a separate store, not retained beyond what your own systems already retain and not used to train any model.
What we do not do.
Short list, stated plainly, so there is nothing to read between the lines of.
We do not move your data out of your own systems.
We do not retain borrower documents once processing is complete.
We do not share your data with unrelated third parties.
We do not train external models on your files or your clients' documents.
We do not sell borrower data, to anyone, for any reason.
Built to the standard your regulator expects.
The same commitments that shape every workflow we build, from the data side specifically.
Borrower financial information is handled under the same safeguarding standard the Gramm-Leach-Bliley Act sets for your own brokerage, since it never leaves systems already covered by your existing safeguards program.
Every automated touch is logged with a timestamp and tied to a consent record, so the question "can you prove this went out correctly" has an answer that takes minutes to produce, not days.
Workflows are built against current RESPA Section 8 guidance. Final legal responsibility for what goes out under your NMLS number remains with your brokerage and your counsel.
The questions a reviewer asks next.
If yours is not here, it goes straight to the person who can actually answer it.
No. Data is used to complete the specific task it was submitted for and is not used to train any model, ours or a third party's.
Yes. Reach out through the contact page and we will get one drafted for your file before anything goes live.
Access is limited to what is directly required to build and support your systems, tied to named accounts, not shared logins and it is revocable by you at any time.
Access is revoked and credentials are rotated. Your data was never moved out of your own CRM and LOS in the first place, so there is nothing to migrate back.
Treat this as the starting point. For anything your reviewer needs in writing, a DPA, specific attestations, or answers to questions not covered here, contact us directly and we will provide it.