Export
Security And Data Protection
How Copperlane protects loan and borrower data: encryption, access control, tenant separation, and how we handle incidents.
Copperlane holds some of the most sensitive data a household ever produces: income, assets, credit, and identity documents. This page describes the controls that protect it.
Customer Separation
Each customer workspace is logically separated. Access requires an authenticated identity and authorization for the relevant workspace and loan. Borrowers can access only their own loan, and lender staff access follows workspace roles and loan permissions.
These controls also apply when Copperlane provides AI-assisted search or guidance. See AI Governance.
Encryption
Data is encrypted in transit with TLS. Data at rest is encrypted in our cloud provider's managed storage, and sensitive fields are protected with managed encryption keys.
Access control
Your staff. Access is granted by member type and by explicit loan access. Administrators manage who is in the workspace and what each person may do. Sign-in is invitation-only: there is no self-service account creation.
Borrowers. A borrower reaches only their own loan, through a scoped session.
Copperlane staff. Internal access is limited to employees with a verified company identity, is used for support and operations, and is separated from the customer-facing application.
Application Security
Copperlane uses layered controls to protect its applications and infrastructure. We monitor dependencies for known vulnerabilities, review material changes before release, and restrict administrative access to authorized personnel.
We perform periodic security reviews and track identified risks through resolution or documented acceptance.
Availability
Service health is published at status.copperlane.ai. We monitor uptime continuously.
Data retention and deletion
Loan and document data is retained for as long as your workspace is active, and as long as your own regulatory retention obligations require. On termination, we delete or return customer data in line with your agreement. Contact your Copperlane representative to begin that process.
Incident response
If we identify a security incident affecting your data, we investigate, contain, and notify affected customers in line with your agreement and applicable law. We tell you what happened, what data was involved, and what we are doing about it.
To report a suspected vulnerability or security issue, email support@copperlane.ai with "Security" in the subject line.
Do not include borrower personal information in a security report. Describe the issue, and we will follow up through a secure channel.