Sensitive data encryption
Sensitive 1003 sections use authenticated AES-256 encryption. Production data keys are generated and protected by AWS KMS, with separate keys for production and preview environments.
Cleotopos combines encryption, strict access controls, malware screening, and verified borrower actions to protect information throughout the application workflow.
Sensitive 1003 sections use authenticated AES-256 encryption. Production data keys are generated and protected by AWS KMS, with separate keys for production and preview environments.
Loan documents stay in private, access-blocked storage encrypted with a customer-managed key. Short-lived signed links provide access without exposing cloud credentials.
Borrower uploads enter quarantine first. Amazon GuardDuty scans each file, and Cleotopos releases it only after a clean result.
Organization boundaries, row-level policies, server-side authorization, and least-privilege cloud roles limit who and what can reach loan information.
What receives added protection
Operational fields remain usable for loan workflows, while high-impact personal information receives an additional application-encryption layer.
Everyday security
Connections use TLS, while databases, backups, and document storage are encrypted at rest.
Sensitive values are masked in the interface and excluded from routine logs and analytics.
Fresh verification is required for high-risk borrower actions, including final application submission.
All Cleotopos AI endpoints are powered by Google Gemini. Google Cloud provides privacy and security capabilities designed to help financial-services customers meet their GLBA obligations.
Talk with us about your brokerage's workflow and security requirements.
Security is an ongoing operating practice. This overview describes current product safeguards and is not a certification or guarantee against every threat.