Security at Viato
Last Updated: August 11, 2026
Our Commitment
Mortgage professionals trust Viato with their pipelines, their client relationships, and their communications. Protecting that data is a core part of how we build and operate the platform. This page summarizes the security measures we have in place.
Independent Security Assessment
Viato is independently assessed under the App Defense Alliance Cloud Application Security Assessment (CASA) framework, most recently completed in June 2026.
CASA is an industry security standard developed by the App Defense Alliance. Validation is performed against the OWASP Application Security Verification Standard and is renewed on an annual cycle.
Data Encryption
- All data is encrypted in transit using TLS
- All data is encrypted at rest using AES-256
- Encryption keys are held in the hosting platform's secret store and injected at runtime. They are never committed to source control or stored in application code
Access Control & Tenant Isolation
- Role based access controls limit every user to the data their role requires
- Customer data is logically isolated per organization, with row level security enforced at the database layer
- Multi factor authentication protects administrative access to production systems
- Internal access to customer data is restricted to a small number of authorized employees on a least privilege basis, and that access is logged
Infrastructure
Customer data is stored exclusively in secure cloud data centers located in the United States, operated by providers certified to SOC 2 and ISO 27001. The application and its background workers run on dedicated United States infrastructure provided by a host certified to ISO/IEC 27001:2022. Physical security at all of these facilities is managed by the providers under their certification programs. Data is protected by encrypted automated backups.
Network Security & Monitoring
- All production traffic passes through an enterprise web application firewall with DDoS protection at the network edge
- Application and infrastructure events are monitored continuously with real time alerting
- Alerts are triaged by severity, with critical issues addressed immediately
Secure Development
- Application code and dependencies are scanned with static analysis and dependency vulnerability scanning as part of our release process
- Findings are remediated based on severity before release
- Production, development, and testing environments are fully separated
Incident Response
We maintain a documented incident response process covering identification, containment, remediation, and notification. Affected customers are notified promptly if an incident involves their data.
Insurance
Viato carries cyber liability insurance covering data breach response in addition to professional and general liability coverage.
Your Data Belongs to You
Your data is your property. We never sell it, share it with other users without your permission, or use it outside the core functionality of the platform. You can request deletion of your data at any time. Full details are in our Privacy Policy.
Data Retention and Deletion
We retain your data for as long as your account is active or as needed to provide the service. Our commitments by data type:
- Account data: retained while your account is active
- Client and contact data: retained until you delete it or close your account
- Files and attachments: retained until you delete them
- Analytics data: aggregated and anonymized after 2 years
- Billing records: retained for 7 years for tax and accounting purposes
- Support communications: retained for 3 years
You can export or delete your data from within the product at any time. On account closure, your data is deleted within 30 days, except where we are required to retain it for legal or regulatory purposes. Full details are in Section 9 of our Privacy Policy.
How AI Features Handle Your Data
Viato uses both self hosted and third party models. We are specific about this rather than general, because the distinction matters when the underlying records are borrower records.
Every third party model provider Viato sends customer content to operates under zero data retention. None of them retain your content, and none of them train on it.
- Viato does not train models on your data. We do not build, fine tune, or improve any model using customer records, client records, or communications content.
- Call recordings and transcripts: when call recording and transcription are enabled, recordings are transcribed by our speech to text service, and the resulting transcript is analyzed by a language model to produce call summaries and insights. Every provider in that path operates under zero data retention, and each is named in the subprocessor register below.
- Assistant and content generation: prompts and the content you direct the assistant to work with are sent to third party model providers to produce the requested output, all of them under zero data retention.
- Human oversight: AI generated content is presented to you for review before it is sent or published.
What zero data retention means
We use that term in a specific sense. A provider operating under zero data retention meets all four of the following:
- Your content is held only in memory for as long as it takes to serve the request
- Prompts and model outputs are not written to persistent storage on the provider side
- Your content is excluded from model training, fine tuning, and evaluation
- Your content is not retained for human review or abuse monitoring
Operational metadata such as request counts and token totals may still be recorded for billing and reliability. That is not content, and it does not include your prompts or the model output.
We verify this standard before a provider is enabled, and we re-check it when a provider changes its terms. Models that do not meet it are blocked and cannot be selected anywhere in Viato, including in workflows and the assistant. We can share the current blocklist on request.
Subprocessors
The following third parties may process customer data on our behalf. All core data storage is located in the United States.
- Supabase: primary database and encrypted file storage, with row level security enforced across tables
- Hostinger: United States server infrastructure running the application and its background workers
- Amazon Web Services: inbound email storage, outbound email delivery, and event notification
- Cloudflare: content delivery, web application firewall, and DDoS protection
- Upstash: rate limiting and request throttling
- Clerk: authentication, session management, and multi factor authentication
- Stripe: subscription payment processing. Card details are entered into Stripe hosted payment surfaces and tokenized, so no card number reaches a Viato server
- Twilio: voice calling, SMS and MMS delivery, and carrier registration
- Slybroadcast: ringless voicemail delivery where you enable it
- Apple Push Notification service and Firebase Cloud Messaging: mobile notification delivery
- Modal: compute for audio transcription
- Deepgram: speech to text
- NVIDIA: model inference
- xAI: call transcript analysis and summarization
- OpenAI, Google, Fireworks AI, and OpenRouter: text generation and embeddings for assistant and content features
- Replicate: image generation for marketing creative
- Pinecone: vector storage supporting in product assistant knowledge
- Sentry: application error monitoring, with personal data capture disabled and server side scrubbing
- Zapier: carries records between your loan origination system and Viato on connections we configure for you, where that system offers no direct API we can use
- Google Workspace and Microsoft 365: email and calendar synchronization through scoped OAuth. Viato never receives or stores your mailbox password, and you can revoke access at any time
- RingCentral and Zoom: calling and meeting data for accounts you connect
- Bundle.social, Meta, and TikTok: social publishing to accounts you connect
- Giphy and Unsplash: stock media search where you use those features
We update this register as our providers change.
Loan Origination System Integrations
Viato connects to loan origination systems and lead sources on your behalf, including LendingPad, Arive, and UWM. Our team configures these connections with your authorization during onboarding, and you can have them disconnected at any time.
Where a loan origination system offers a direct API and Viato supports it, we use it, because it is the shortest path and puts no third party between your system and ours. Where that is not available, an automation bridge is the only supported route, and we use Zapier for that. A connection is therefore established in one of three ways:
- Direct API integration between Viato and your loan origination system, currently available for Arive. No intermediary is involved
- Zapier to Viato: Zapier passes records from your loan origination system to a Viato webhook
- Loan origination system to Zapier: your system sends records to Zapier, which forwards them to Viato
LendingPad records reach Viato through Zapier, or through a file import performed by you or by our team.
However the connection is made, the same commitments apply to the borrower records that arrive through it:
- You remain the controller of borrower data. Viato processes LOS sourced borrower records solely to provide the platform to you and on your instructions. We do not use borrower data for our own purposes, and we do not use it to train models
- Scope: each integration receives and returns only the fields required for that integration to function. Records are stored under your organization and are subject to the same tenant isolation and encryption described above
- Onward handling: the originating system remains governed by its own terms and its agreement with you. Viato does not alter or supersede those terms
- Deletion: borrower records imported from an LOS are deleted on the same schedule as your other client data, including deletion within 30 days of account closure
Questions about how a specific loan origination system connection handles your borrower data can be sent to the address below.
Contracts and Documentation
Every Viato account is governed by our Terms of Service and Privacy Policy. Those documents, together with this page, are our data handling commitments, and they apply to every customer without a separate agreement to sign.
Organizations with specific contractual requirements around data processing, and anyone who wants documentation from our most recent independent assessment, can reach us at privacy@viato.ai.
Questions or Reports
To report a suspected vulnerability, contact us at privacy@viato.ai. When testing, please do not access, modify, or retain data that is not yours, and give us reasonable time to address an issue before publishing it.
Security Summary
- Independently assessed under the App Defense Alliance CASA framework, renewed annually
- Encrypted in transit (TLS) and at rest (AES-256)
- Role based access with per tenant isolation enforced at the database
- Customer data stored with SOC 2 and ISO 27001 certified providers, in US data centers
- Continuous monitoring with WAF and DDoS protection
- Named subprocessor register, with US based core data storage
- No model training on customer data
- Data deleted within 30 days of account closure
- Cyber liability insurance carried
Ready to work smarter?
Join the LOs who stopped juggling and started closing.