Security at CliQloan

Loan files hold some of the most sensitive data a borrower shares. CliQloan is built by AmitaSoft to protect it, and our controls have been independently examined under SOC 2 Type 2.

SOC 2 Type 2 examination

AmitaSoft completed a SOC 2 Type 2 examination performed by Atom Assurances LLC, an independent CPA firm. The examination tested whether our controls were suitably designed and operated effectively over the period May 15, 2026 to August 28, 2026.

Report type
SOC 2 Type 2
Trust services criteria
Security, Availability, Processing Integrity and Confidentiality
Observation period
May 15, 2026 to August 28, 2026
Scope
The AmitaSoft platform, including CliQloan, SafeVault and TaxFlo

The full report is available to customers and prospects on request, under NDA. Request the report

How we protect loan data

Encryption

Data is encrypted in transit with TLS 1.2 or 1.3 and at rest with AES-256, including databases and stored documents.

Access control

Access follows least privilege with role-based permissions. Multi-factor authentication is required for critical systems and admin access, and permissions are reviewed on a set schedule.

Monitoring and incident response

Infrastructure and sign-in activity are logged and monitored with alerts. Security events follow a documented incident response process, from detection and triage through recovery and post-incident review.

Backups and recovery

Production databases have automated, encrypted backups with point-in-time recovery, and backup failures trigger alerts.

Independent security testing

Third-party vulnerability scanning and web application penetration testing are performed, and findings are risk-rated and tracked to remediation.

Secure development

Every code change is peer reviewed and tested in a staging environment before it reaches production.

Your data stays separated

Each customer's data is logically separated from other customers. When a borrower's data moves between AmitaSoft products, such as documents shared from SafeVault into a loan file, it moves only with that person's authorization.

Our people

Everyone with system access signs a confidentiality agreement, completes security awareness training at onboarding and every year, and has access removed when they leave.

Hosting and service providers

CliQloan runs on Amazon Web Services. These providers process data to deliver specific features:

ProviderPurpose
Amazon Web ServicesCloud hosting, databases and document storage
CredcoCredit reports
DocuSignE-signature
StripeSubscription billing for CliQloan customers

Frequently asked questions

Is CliQloan SOC 2 compliant?

AmitaSoft, the company behind CliQloan, completed a SOC 2 Type 2 examination performed by an independent CPA firm, covering Security, Availability, Processing Integrity and Confidentiality for May 15, 2026 to August 28, 2026.

Can I get a copy of the SOC 2 report?

Yes. Customers and prospects can request the full report through our contact page. We share it under NDA.

How is borrower data encrypted?

Data is encrypted in transit with TLS 1.2 or 1.3 and at rest with AES-256, including databases and stored documents.

Where is CliQloan hosted?

CliQloan runs on Amazon Web Services.

Do appraisers and escrow get access to the whole loan file?

No. Third parties get a secure link to their own task in the loan file and complete it without a CliQloan account.

Security questions from your team?

We can walk your compliance or IT reviewer through our controls and share the SOC 2 report under NDA.

Request the SOC 2 report