Tier 1 SystemsAccess
Public Document

Privacy Policy

Last Updated: July 12, 2026

This Privacy Policy explains how Tier 1 Systems LLC ("Tier 1 Systems," "we," "us," or "our") collects, uses, discloses, and safeguards information in connection with MaRiON and the other software platforms we operate (collectively, the "Service"). This policy applies to visitors to tier1systems.ai, to authorized users of the Service acting on behalf of a customer organization, and to individuals whose information is processed through the Service on a customer's behalf.

01

Data Classification

We classify information handled by the Service into four tiers, each with a corresponding minimum handling standard:

  • Public — information intended for public distribution (e.g. this policy, our marketing site). No confidentiality controls required.
  • Internal — operational data not intended for external release (e.g. aggregated, de-identified usage metrics). Access limited to authorized personnel.
  • Confidential — customer account data, business contact information, and support communications. Access restricted on a least-privilege, need-to-know basis and logged.
  • Restricted — personal financial information, loan file contents, government identification numbers, and other data submitted to MaRiON for loan origination and underwriting workflows. Subject to the strictest access, encryption, and audit-logging controls described in Section 5.
02

Information We Collect

We collect the following categories of information:

  • Account & Authentication Data — name, work email address, and Google Workspace identity information provided when you sign in to the Command Center via Google Sign-In.
  • Loan & Client Data — information submitted to MaRiON by authorized users or their clients in the course of structuring and processing a loan, which may include names, contact details, financial information, and communications with clients and real estate agents. We process this data solely as directed by the customer organization on whose behalf it was submitted.
  • Usage Data — log data such as pages visited, features used, timestamps, and device/browser information, collected automatically as part of operating and securing the Service.
  • Support & Communications Data — information you provide when submitting a support ticket (through MaRiON's automated ingestion channel) or otherwise contacting us.
  • Compliance Inquiry Data — name, work email, company, and request details submitted through our Trust Center compliance documentation request form.

We limit collection of personal information to what is reasonably necessary to operate the Service, support our customers, and meet our legal and contractual obligations. We do not collect government identification numbers, financial account numbers, or other Restricted-tier data except where a customer organization submits it directly to MaRiON as part of the loan origination workflow they control.

03

How We Use Information

  • To provide, operate, and maintain the Service.
  • To authenticate users and enforce access controls limiting the Command Center to authorized personnel.
  • To structure loan files, generate underwriting-ready summaries, and manage client and Realtor communications on behalf of the customer organization directing that processing.
  • To detect, investigate, and prevent security incidents, fraud, and unauthorized access.
  • To respond to support requests and compliance documentation inquiries.
  • To comply with applicable law, regulation, legal process, or enforceable governmental request.

We do not sell personal information, and we do not use Restricted or Confidential-tier data to train general-purpose machine learning models outside the customer relationship it was collected under.

04

Sub-Processors & Disclosure

We use a limited set of sub-processors to operate the Service. Each sub-processor is contractually bound to protect data consistent with the standards in this policy. As of the date above, our sub-processors include:

Sub-ProcessorPurpose
Google LLCWorkspace-based identity authentication (Google Sign-In) for Command Center access.
Cloud Infrastructure ProviderApplication hosting and managed database services. Final provider(s) will be published here prior to General Availability.

This table is reviewed and updated whenever a sub-processor is added, replaced, or removed. We do not disclose Confidential or Restricted-tier data to any party not listed above except as required by law.

05

Data Security

We apply the following technical and organizational controls to Confidential and Restricted-tier data:

  • Encryption in transit — all connections to the Service are encrypted using TLS 1.3 (or TLS 1.2 where required for compatibility), with plaintext HTTP connections rejected.
  • Encryption at rest — data stored in our production database is encrypted at rest using AES-256 by our infrastructure provider.
  • Access control — Command Center access is restricted to authenticated users on an authorized corporate domain, enforced independently at both authentication and on every subsequent request.
  • Logging — authentication events, access denials, and material data changes are recorded in an append-only audit log.
  • Least privilege — service-to-service integrations (such as MaRiON's ticket ingestion channel) authenticate using scoped, rotatable credentials rather than shared user accounts.

No system is perfectly secure. We maintain an incident response process designed to detect, contain, and remediate security incidents promptly.

06

Data Retention

  • Account and authentication data is retained for the duration of the customer relationship and for 90 days afterward to support account recovery and legal/audit obligations, after which it is deleted or irreversibly de-identified.
  • Loan and client data submitted to MaRiON is retained per the data retention terms agreed with the customer organization that submitted it, and in the absence of a specific term, for 7 years to meet common mortgage industry recordkeeping obligations.
  • Audit log entries are retained for 365 days on a rolling basis.
  • Backups are retained on a rolling schedule and purged no later than 90 days after creation.

Specific retention commitments for a given customer are governed by that customer's order form or data processing agreement, which controls over the defaults above in the event of a conflict.

07

Data Breach Notification

If we become aware of a security incident resulting in unauthorized access to, or acquisition of, Confidential or Restricted-tier data, we will notify affected customer organizations without undue delay and, except where a longer period is required to accurately assess scope, no later than 72 hours after we become aware of the incident. Notification will include, to the extent known, the nature of the incident, categories of data involved, and steps taken or recommended in response. This commitment does not limit any additional or faster notification obligation imposed by applicable law.

08

Your Choices & Rights

Depending on your jurisdiction and relationship to the Service, you may have rights to access, correct, export, or request deletion of personal information we hold about you. Because MaRiON is typically used by our customers to process data on behalf of their own clients, if you are a client of one of our customers, please direct requests to that organization in the first instance; we will support them in fulfilling verified requests. Authorized Command Center users may contact us directly at the address in Section 12.

09

Children's Privacy

The Service is intended for business use by adults acting on behalf of a customer organization. We do not knowingly collect personal information from individuals under 16.

10

International Data Transfers

We currently operate and store data within the United States. If this changes, we will update this policy and implement appropriate safeguards for any cross-border transfer of personal information.

11

Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last Updated" date above, and where required by law or contract, we will provide additional notice to affected customers.

12

Contact

Questions about this policy or requests regarding your personal information can be sent to privacy@tier1systems.ai.