Security built for production valuation work
Banks Technologies designs and operates cloud platforms where lenders, AMCs, and appraisers trust us with sensitive order, property, and client data. Security is part of how we build — not an afterthought.
Last updated: July 10, 2026
Our commitment
Valuation technology handles regulated, high-stakes information every day. We combine industry experience with modern cloud security practices so teams can move faster without sacrificing confidentiality, integrity, or availability.
We maintain a formal security and compliance program, including SOC 2 readiness, and review our controls regularly as our products and customer base grow.
Platform overview
Our primary production platform is ECHO (app.withecho.com) — order and operations management for valuation teams. Related products include HomeVault and Insight. Customer and tenant data for these services is hosted in Microsoft Azure (United States regions).
Infrastructure & environment isolation
- Cloud hosting: Microsoft Azure with dedicated production and non-production environments.
- Environment separation: Production and test workloads run in separate Azure subscriptions with no network peering between them.
- Production ingress: Customer traffic to ECHO production enters through Azure Front Door with a Web Application Firewall (WAF) in active prevention mode.
- Database access: Production PostgreSQL is reachable only from private network paths — not exposed to the public internet.
- Secrets management: Production credentials and keys are stored in Azure Key Vault, not in application source code.
Encryption
- In transit: TLS 1.2 or higher for all customer-facing web and API endpoints.
- At rest: Azure-managed encryption (AES-256) for databases, storage, and backups.
- Backups: Geo-redundant database backups with defined retention to support recovery objectives.
Identity, access & tenant isolation
- Authentication: Workforce and customer sign-in through industry-standard identity providers (Microsoft Entra ID and Auth0), with multi-factor authentication required for critical systems.
- Authorization: Role-based access control in application code — users see only what their role and organization permit.
- Multi-tenant isolation: Database Row-Level Security (RLS) enforces organization boundaries so one tenant cannot access another's data.
- Privileged access: Production changes require documented approval and tracked change tickets.
- Access reviews: We perform periodic reviews of who has access to critical systems.
Secure development & vulnerability management
- Code review: Changes are reviewed and tested before release; production promotion follows a controlled release path.
- Automated testing: Continuous integration runs on code changes before merge.
- Dependency monitoring: Automated vulnerability scanning (e.g. GitHub Dependabot) with remediation timelines for identified issues.
- Audit logging: Sensitive access and administrative actions are logged for investigation and compliance.
Monitoring & availability
- Uptime monitoring on production endpoints with alerting to our operations team.
- Structured logging for application and security-relevant events.
- Public status page: status.bankstechnologies.ai — current service health and incident updates.
If we experience a material service disruption, we communicate through the status page and direct outreach to affected customers as appropriate.
Privacy & your data rights
Our Privacy Policy describes what we collect and how we use it.
Data deletion requests: Email legal@bankstechnologies.ai with subject line Data Deletion Request. We acknowledge requests within five business days and complete verified requests within thirty days where applicable.
We use application-level soft delete for many records and retain audit and security logs as required for compliance and operational integrity.
Compliance & third-party services
- SOC 2: Banks Technologies maintains a SOC 2 compliance program with ongoing control monitoring and independent audit.
- Vendor review: We use established cloud and SaaS providers (including Azure, GitHub, and Auth0) and review the security posture of vendors that process customer data.
- Responsible AI: Where we apply automation in valuation workflows, outputs are grounded in source data, human review remains in the loop for professional judgment, and actions are logged with attribution.
Report a security concern
If you believe you have found a security vulnerability or have a security-related concern about Banks Technologies services, contact us at:
legal@bankstechnologies.ai
Subject: Security Report
Please include a description of the issue, the affected product or URL, and your contact information. We investigate good-faith reports promptly and will not retaliate against researchers who follow responsible disclosure practices.
For general support or account questions, use Contact Us on our main site.