![]()
|
Security, GLB & Patriot Act ComplianceAt a la mode, we take the job of protecting your data and that of your customers very seriously. We have implemented systems and policies to ensure that your data is safe and compliant. Mortgage XSites fully comply with the FTC regulations regarding the Gramm-Leach-Bliley Act. The following document describes the areas affected and falling under the Act along with a description of how we safeguard data and maintain compliance. Protection from unauthorized access during the application entry process
Protection from unauthorized access while in our custody
Once in our custody, electronic access to the data is restricted to key personnel who develop and maintain the systems. We implement a hardware firewall solution that prevents direct access to any of the database servers from outside the building.
Physical access to the data is protected in our network operations center by multiple layers of security. Physical access from outside the building to the general offices is secured by electronic card access. Anyone without a security badge is not even able to enter the general offices. Once inside the general offices, access to the network center itself is again limited by card access to key personnel who maintain the systems. Logs are kept of all access to any door.
Use of loan application data by a la mode
Under no circumstances does a la mode, sell, convey, share or disseminate in any way, any data associated with your Mortgage XSite or clients' loan applications. We are in the business of providing software solutions for the real estate industry and have been a conscientious and trustworthy custodian of customer data since 1985.
As part of a la mode's process of continued enhancements and upgrades to the Mortgage XSites and FlexApp 1003 products, we monitor and compile various statistics on the habits of consumers filling out the loan application. These statistics such as which fields are left blank, most common stopping points, most common data entry formats and various other user habits, don't contain any confidential consumer information but provide us with a wealth of information we need to improve the product. In addition we reserve the right to aggregate certain data points for the purposes of measuring the level of growth of our products and tracking trends industry wide in the habits of consumers.
Protection while exporting loan applications to a loan origination system (LOS)
Mortgage XSites supports exporting loan applications to a number of popular LOS systems such as Calyx Point, Encompass, Contour, Genesis 2000, BytePro, and many others. Depending on the specific LOS, the export methods vary. For Encompass, Contour and Genesis 2000, the export occurs using a direct interface to Ellie Mae's ePass network. This interface occurs across an encrypted SSL connection to their back end servers. Likewise for BytePro, an encrypted SSL connection from the BytePro desktop software is made directly to the a la mode servers. Various other LOS systems such as Calyx Point utilize the Fannie Mae DO/DU 3.2 format for importing loan applications, in this case the DO/DU file is downloaded from the a la mode servers to your local computer over a secure HTTPS connection.
Protecting data from power failure and disaster
Mortgage XSites are hosted at a la mode's state of the art data center located in Oklahoma City, Oklahoma. In addition, a la mode also has two other offices in Orlando and Salt Lake City, as well as a leased backup data center which is also in Oklahoma. Each of the data centers houses at least one redundant system and boasts redundant power employing uninterruptible power supplies and generators capable of supplying them with power for an indefinite period of time. In the event of a disaster affecting the physical location of the Oklahoma City data center, a la mode is capable of becoming fully functional by employing a combination of the three alternate data centers.
USA PATRIOT Act Compliance Definitions
DirectFax Gramm-Leach-Bliley (Hypertext Transfer Protocol over Secure Socket Layer, or HTTP over SSL) is a Web protocol, developed by Netscape, built into browsers, that encrypts and decrypts user page requests as well as the pages that are returned by the Web server. HTTPS is the use of Secure Socket Layer (SSL) as a sub-layer under its regular HTTP application layering. (HTTPS uses port 443 instead of HTTP port 80 in its interactions with the lower layer, TCP/IP.)
Secure Sockets Layer. Used by most commerce servers on the World Wide Web, this high-level security protocol protects the confidentiality and security of data while it is being transmitted through the internet. Based on RSA Data Security's public-key cryptography, SSL is an open protocol that has been submitted to several industry groups as the industry security standard. Denoted by the letters HTTPS in the URL.
USA PATRIOT Act |
|
HomeNews Search Terms of Use Site Map Subscribe Find a Real Estate Professional Contact Us |