Privacy & Security

Privacy & Security

How Lendarex protects your data and maintains the security of your underwriting platform.

Security Measures Active

Platform Security

Encrypted Sessions
Signed session cookies with HTTPS enforcement and HttpOnly flags prevent unauthorized access.
Inactivity Timeout
Sessions automatically expire after 30 minutes of inactivity to protect unattended workstations.
Rate-Limited Login
Login attempts are limited to 5 per minute per IP address to prevent brute-force attacks.
Bcrypt Password Hashing
User passwords are hashed with bcrypt using salted rounds, never stored in plain text.
User Isolation
Per-user data isolation ensures users can only access deals and data assigned to their account.
Admin-Only Controls
User management, scoring models, and system settings are restricted to admin accounts only.
Two-Factor Authentication (2FA)
Any user can enable optional TOTP-based two-factor authentication (authenticator app) on their account, with one-time backup codes for recovery. Secrets are encrypted at rest.
Security Audit Log
Security-relevant events — logins (success and failure), logouts, 2FA changes, and audit exports — are recorded with timestamp and source IP. Admins can review and export the log.

Data Collection & Processing

Lendarex processes the following categories of data as part of mortgage underwriting:

  • Mortgage Documents: Applications, appraisals, credit reports, condo status certificates, bank statements, purchase agreements, and Letters of Intent uploaded for automated extraction and analysis.
  • Borrower Information: Names, addresses, employment details, income, net worth, and credit data extracted from uploaded documents for deal scoring.
  • Property Information: Addresses, appraisal values, comparable sales data, and property images used for valuation and risk assessment.
  • User Account Data: Usernames, display names, and hashed passwords stored for authentication purposes.
  • Background Check Data: NameScan PEP/Sanctions screening results and broker verification records.

AI Processing

Lendarex uses AI services (Claude by Anthropic) for the following features:

  • Deal summary and risk analysis generation
  • Purview appraisal review analysis
  • Bank statement financial assessment
  • Condo status certificate flagging
  • Broker notes risk scanning
  • Purchase agreement analysis
  • Photo quality assessment
  • Legal risk intelligence
  • Investor summary narratives
  • Help chatbot (Rex) assistance

Document content sent to AI services is processed in real-time and is not stored or used for training by the AI provider, in accordance with their enterprise data policies. All AI-generated outputs are stored within your Lendarex database only.

Our Data Privacy Commitment

No Third-Party Data Sharing

Lendarex does not sell, share, or distribute your data to any third parties. Your mortgage deal information, borrower data, and uploaded documents remain entirely within your Lendarex environment. We are committed to maintaining the confidentiality and security of all information processed through our platform.

  • Your data is never sold or shared with third parties for marketing, analytics, or any other purpose.
  • All data remains stored exclusively in your secure database and file storage.
  • External service integrations (such as geocoding or AI analysis) process data in real-time only and do not retain or store your information.
  • AI providers operate under enterprise data policies that prohibit using your data for model training.

Encryption & Data in Transit

All communication between your browser and the Lendarex platform is encrypted using HTTPS/TLS, ensuring that your data is protected in transit. Session cookies are signed, HttpOnly, and transmitted only over secure connections. Your database is secured with encrypted connections and access is restricted to authenticated application processes only.

Sensitive credentials stored by the platform — such as third-party integration tokens and two-factor authentication secrets — are encrypted at rest using authenticated symmetric encryption (Fernet/AES). Backup codes are stored only as one-way bcrypt hashes.

Data Residency — Canada

The hosted Lendarex platform runs in a Canadian data region (Toronto, Canada). Your PostgreSQL database, uploaded documents, and property images are stored within Canada. This supports Canadian lenders with data-residency requirements under PIPEDA and provincial privacy regimes (including Quebec's Law 25).

AI analysis is performed by third-party providers (e.g. Anthropic) that may process content outside Canada in real time under enterprise data agreements that prohibit retention or training on your content; no document content is stored by those providers. Lenders requiring all processing to remain in Canada can disable AI features or discuss a dedicated deployment with their account manager.

Data Storage & Retention

  • All deal data, scores, and extracted fields are stored in a PostgreSQL database.
  • Uploaded documents and property images are stored on the server file system.
  • Data is retained until explicitly deleted by an authorized user through the dashboard.
  • Session cookies expire after 7 days or 30 minutes of inactivity, whichever occurs first.

Your Rights & Contact

As a user of Lendarex, you have the right to:

  • Request access to your stored data
  • Request deletion of your deals and associated data
  • Update your account information through Settings
  • Request a copy of data associated with your account

For privacy or security inquiries, contact your system administrator.

Last updated: March 2026