Security architecture
Encryption at rest
All property data, photos, and consumer information stored using AES-256 encryption. Encryption keys are managed through dedicated key management infrastructure with automatic rotation.
Encryption in transit
All data transmitted between the mobile app, processing engines, and delivery endpoints is encrypted using TLS 1.3. No unencrypted data ever leaves the device.
Role-based access controls
Access to property data and consumer information is restricted by role. Appraisers see only their assigned inspections. Administrators see only their organization's data. No cross-tenant data access is possible.
Audit logging
Every data access event, modification, and export is logged with user identity, timestamp, and action type. Audit logs are immutable and retained for compliance review.
US-based infrastructure
All data is stored in SOC 2 compliant cloud infrastructure within the United States. Data does not leave US jurisdiction. Geographically separate backup regions ensure business continuity.
Data minimization
BALVIN AI collects only the property attribute data necessary for UAD 3.6 compliance and valuation purposes. Consumer-identifiable information is segregated from property attribute data at the architecture level.
Gramm-Leach-Bliley Act compliance
The Gramm-Leach-Bliley Act (GLB) requires financial institutions — including mortgage lenders, servicers, and their technology providers — to protect the security and confidentiality of consumers' nonpublic personal information (NPI). BALVIN AI is designed to support GLB compliance across all three provisions.
| GLB provision | Requirement | How BALVIN AI complies |
|---|---|---|
| Safeguards Rule | Develop, implement, and maintain a comprehensive information security program to protect NPI | AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, immutable audit logs, regular vulnerability assessments, and incident response procedures |
| Privacy Rule | Provide consumers with clear notice about data collection, use, and sharing practices | BALVIN AI supports lender and AMC disclosure requirements by providing clear documentation of what data is collected during inspections, how it is processed, and with whom it is shared. Consumer-facing privacy notices can be configured per organization |
| Pretexting Provisions | Protect against unauthorized access to NPI through false pretenses | Multi-factor authentication, device-level verification, GPS-stamped inspection records, and biometric or credential-based appraiser identity verification prevent unauthorized data access |
Consumer data rights & transparency
BALVIN AI is committed to consumer transparency. When property data is collected during an inspection, consumers have the right to understand what information is being gathered and how it will be used.
What data is collected
During a BALVIN AI property inspection, the following data is captured: property photos (interior and exterior), AI-detected property attributes (flooring type, appliance condition, HVAC systems, roof condition, room dimensions, interior layout), GPS coordinates and timestamps for fraud-proof verification, and property address and identification data necessary for the appraisal or inspection report.
How data is used
Property data captured through BALVIN AI is used for: generating UAD 3.6 compliant property condition reports, producing MISMO 3.6 XML for GSE submission, creating valuation reports (PCR, AVR, EVR) as ordered by the lender or AMC, and supporting quality control and compliance auditing by the ordering institution. Data is processed by BALVIN's computer vision engine to detect and classify property attributes automatically.
How data is shared
Property inspection data is shared only with: the ordering institution (lender, AMC, or servicer that requested the inspection), GSEs (Fannie Mae, Freddie Mac) through the UCDP submission process, and authorized third parties as directed by the ordering institution and permitted by applicable law. BALVIN AI does not sell consumer data to third parties.
Consumer notice
BALVIN AI provides tools for lenders and AMCs to deliver consumer privacy notices in compliance with the GLB Privacy Rule. These notices inform homeowners and borrowers about the data collection process before or at the time of inspection, the types of information being collected, how the information will be used and with whom it may be shared, and their rights regarding their personal information.
Additional compliance frameworks
| Framework | Status |
|---|---|
| Gramm-Leach-Bliley Act (GLB) | Compliant by Design |
| SOC 2 Type II | Infrastructure Compliant |
| MISMO 3.6 XML | Native Output Format |
| UAD 3.6 (GSE Mandate) | Purpose-Built Compliance |
| UCDP / EAD Submission | Direct Delivery Compatible |
| CCPA / State Privacy Laws | Consumer Rights Supported |
| ECOA / Fair Lending | AI Bias Testing and Monitoring |
Frequently asked questions
Is BALVIN AI compliant with the Gramm-Leach-Bliley Act?
How does BALVIN AI protect consumer data?
Are consumers informed about data collection?
Does BALVIN AI sell consumer data?
Where is data stored?
Does BALVIN AI address fair lending and AI bias?
Need a detailed security review?
Enterprise security documentation, SOC 2 reports, and data processing agreements are available for qualified institutions.
Request security documentation