Security
Security and privacy
Borrower documents are sensitive. This page says plainly how they’re handled today and how to reach us. We’d rather be accurate than impressive.
Our approach
- AI suggests, a person approves. Values read from documents are for you to check.
- The minimum data. We only ask for and keep what the work needs.
- Plain facts. This page only describes what the product does today.
Where borrower documents go
These services process borrower information when the app is used:
| Service | What it receives | Why | Where |
|---|---|---|---|
| Anthropic (Claude API) | While a borrower uploads: each file (first 3 pages), the applicants' names, the loan purpose and income types | Recognize each document and sort it into the broker's checklist; the result isn't stored | [NOT CONFIRMED] |
| Cloudflare (R2 storage) | Submitted documents and application details (names, emails, phone numbers, income types, notes, consent); broker profile photos | Store each submission for the broker | [NOT CONFIRMED] |
| Resend (email) | Broker names and emails for sign-in links; submission emails to the broker with client names, emails, phone numbers, file names and notes | Send sign-in links and tell the broker when documents arrive | [NOT CONFIRMED] |
| Supabase (database) | Broker accounts and profiles, encrypted Finmo credentials, sign-in sessions, audit and delivery records, encrypted copies of delayed submissions | Run broker accounts and deliver submissions | [NOT CONFIRMED] |
| Railway (app hosting) | All app traffic, including uploads in transit, and server logs | Run the app | [NOT CONFIRMED] |
| Google (Google Fonts) | IP address and browser details of anyone who opens the app | Load the app's fonts | [NOT CONFIRMED] |
| Finmo | Borrower details and documents, when the broker sends a file | Fill in the broker's Finmo deal, using the broker's own credentials | [NOT CONFIRMED] |
Today
-
Each submission is kept separate
Borrowers upload through your link, and each submission is delivered as its own package, named for its applicants.
Your responsibilities as the broker
Privacy contact
Questions about personal information: Arash Zare, President, info@thebrokermate.com.
Report a security problem
Email info@thebrokermate.com. Please include what you found, how to reproduce it, and any accounts or URLs involved. Don’t include borrower documents or personal information.
We’ll acknowledge your report and keep you updated. We won’t pursue legal action against good-faith research that avoids harming people’s data and gives us reasonable time to fix the problem.
Machine-readable contact: security.txt