BBALVIN.AI
HomeData protection & compliance
Security & compliance

Data protection, privacy & compliance.

BALVIN AI is built for the regulated mortgage industry. Every layer of the platform — from data capture to storage to delivery — is designed to protect nonpublic personal information and comply with federal data protection requirements.

01

Security architecture

Encryption at rest

All property data, photos, and consumer information stored using AES-256 encryption. Encryption keys are managed through dedicated key management infrastructure with automatic rotation.

Encryption in transit

All data transmitted between the mobile app, processing engines, and delivery endpoints is encrypted using TLS 1.3. No unencrypted data ever leaves the device.

Role-based access controls

Access to property data and consumer information is restricted by role. Appraisers see only their assigned inspections. Administrators see only their organization's data. No cross-tenant data access is possible.

Audit logging

Every data access event, modification, and export is logged with user identity, timestamp, and action type. Audit logs are immutable and retained for compliance review.

US-based infrastructure

All data is stored in SOC 2 compliant cloud infrastructure within the United States. Data does not leave US jurisdiction. Geographically separate backup regions ensure business continuity.

Data minimization

BALVIN AI collects only the property attribute data necessary for UAD 3.6 compliance and valuation purposes. Consumer-identifiable information is segregated from property attribute data at the architecture level.

02

Gramm-Leach-Bliley Act compliance

The Gramm-Leach-Bliley Act (GLB) requires financial institutions — including mortgage lenders, servicers, and their technology providers — to protect the security and confidentiality of consumers' nonpublic personal information (NPI). BALVIN AI is designed to support GLB compliance across all three provisions.

GLB provisionRequirementHow BALVIN AI complies
Safeguards RuleDevelop, implement, and maintain a comprehensive information security program to protect NPIAES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, immutable audit logs, regular vulnerability assessments, and incident response procedures
Privacy RuleProvide consumers with clear notice about data collection, use, and sharing practicesBALVIN AI supports lender and AMC disclosure requirements by providing clear documentation of what data is collected during inspections, how it is processed, and with whom it is shared. Consumer-facing privacy notices can be configured per organization
Pretexting ProvisionsProtect against unauthorized access to NPI through false pretensesMulti-factor authentication, device-level verification, GPS-stamped inspection records, and biometric or credential-based appraiser identity verification prevent unauthorized data access
03

Consumer data rights & transparency

BALVIN AI is committed to consumer transparency. When property data is collected during an inspection, consumers have the right to understand what information is being gathered and how it will be used.

What data is collected

During a BALVIN AI property inspection, the following data is captured: property photos (interior and exterior), AI-detected property attributes (flooring type, appliance condition, HVAC systems, roof condition, room dimensions, interior layout), GPS coordinates and timestamps for fraud-proof verification, and property address and identification data necessary for the appraisal or inspection report.

How data is used

Property data captured through BALVIN AI is used for: generating UAD 3.6 compliant property condition reports, producing MISMO 3.6 XML for GSE submission, creating valuation reports (PCR, AVR, EVR) as ordered by the lender or AMC, and supporting quality control and compliance auditing by the ordering institution. Data is processed by BALVIN's computer vision engine to detect and classify property attributes automatically.

How data is shared

Property inspection data is shared only with: the ordering institution (lender, AMC, or servicer that requested the inspection), GSEs (Fannie Mae, Freddie Mac) through the UCDP submission process, and authorized third parties as directed by the ordering institution and permitted by applicable law. BALVIN AI does not sell consumer data to third parties.

Consumer notice

BALVIN AI provides tools for lenders and AMCs to deliver consumer privacy notices in compliance with the GLB Privacy Rule. These notices inform homeowners and borrowers about the data collection process before or at the time of inspection, the types of information being collected, how the information will be used and with whom it may be shared, and their rights regarding their personal information.

Data retention: Property inspection data is retained in accordance with the ordering institution's data retention policies and applicable regulatory requirements. Organizations can configure retention periods through the BALVIN AI enterprise dashboard. Upon expiration, data is securely deleted using industry-standard data destruction methods.
04

Additional compliance frameworks

FrameworkStatus
Gramm-Leach-Bliley Act (GLB)Compliant by Design
SOC 2 Type IIInfrastructure Compliant
MISMO 3.6 XMLNative Output Format
UAD 3.6 (GSE Mandate)Purpose-Built Compliance
UCDP / EAD SubmissionDirect Delivery Compatible
CCPA / State Privacy LawsConsumer Rights Supported
ECOA / Fair LendingAI Bias Testing and Monitoring
05

Frequently asked questions

Is BALVIN AI compliant with the Gramm-Leach-Bliley Act?
Yes. BALVIN AI is designed to comply with all three GLB provisions: the Safeguards Rule (comprehensive security program), the Privacy Rule (consumer notice and disclosure), and the Pretexting Provisions (preventing unauthorized access). All NPI is encrypted, access-controlled, and audit-logged.
How does BALVIN AI protect consumer data?
AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, multi-factor authentication, immutable audit logs, and data minimization principles. Consumer-identifiable information is architecturally segregated from property attribute data.
Are consumers informed about data collection?
Yes. BALVIN AI provides tools for lenders and AMCs to deliver consumer privacy notices before or at the time of inspection, in compliance with GLB Privacy Rule requirements. These notices explain what data is collected, how it is used, and with whom it is shared.
Does BALVIN AI sell consumer data?
No. BALVIN AI does not sell consumer data to third parties. Property inspection data is shared only with the ordering institution, GSEs through the UCDP submission process, and authorized parties as directed by the ordering institution and permitted by law.
Where is data stored?
All data is stored in SOC 2 compliant cloud infrastructure within the United States. Data does not leave US jurisdiction. Geographically separate backup regions ensure disaster recovery and business continuity.
Does BALVIN AI address fair lending and AI bias?
Yes. BALVIN AI's computer vision models are tested for bias in property attribute detection across property types, neighborhoods, and demographics. The platform is designed to comply with the Equal Credit Opportunity Act (ECOA) and fair lending requirements, and AI model outputs are monitored for disparate impact.

Need a detailed security review?

Enterprise security documentation, SOC 2 reports, and data processing agreements are available for qualified institutions.

Request security documentation