Trust & Security
MaRiON handles sensitive loan and client data on behalf of the mortgage professionals who rely on it. This page summarizes how we protect that data and where we stand in our compliance program.
Data Encryption
All traffic to the Service is encrypted in transit using TLS 1.3. Data at rest in our production database is encrypted using AES-256 by our infrastructure provider. Encryption keys are managed by that provider, not embedded in application code.
Access Controls
Command Center access requires Google Workspace single sign-on restricted to an authorized corporate domain. The access rule is enforced independently at both sign-in and on every subsequent request, so a misconfiguration in one layer cannot silently widen access.
Vulnerability Management
We track dependency vulnerabilities via automated auditing on every build and patch on a risk-prioritized basis. We welcome responsible disclosure of security issues — see the contact address below.
Logical Access Logging
Authentication events, access denials, and material data changes within the Command Center are written to an append-only audit log capturing timestamp, actor, event type, and originating IP address.
Compliance Status
SOC 2 Type 1 — In Progress
Tier 1 Systems is actively preparing for a SOC 2 Type 1 examination against the Trust Services Criteria, including the logical access controls (CC6.1–CC6.3) described above. We have not yet completed an examination and do not represent that we hold SOC 2 certification today. Customers evaluating us for compliance purposes should request our current control documentation using the form below rather than relying on this page alone.
Request Documentation
Request Compliance Documentation
Under an NDA, we can share our current security control documentation and SOC 2 readiness materials with prospective and current customers. Tell us what you need below.
Found a security issue? Report it to security@tier1systems.ai. For general privacy questions, see our Privacy Policy.