EntityScan AI provides AI-powered borrower entity document review for commercial real estate lenders. This Trust Center is built for the security and compliance expectations of banks, credit unions, and private lenders: review our security posture, confirm our SOC 2 Type II examination, and request access to our security documentation, including the full SOC 2 Type II report, as part of vendor due diligence.
Data Security
Customer data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256. Customer environments are logically isolated through application-level and cloud-level controls.
AI
EntityScan AI uses enterprise-grade AI models from third-party providers, accessed via secure encrypted APIs under enterprise data-protection terms. Customer data is never routed through consumer AI chat products. Customer data is not used to train, fine-tune, or improve public, shared, or third-party foundation models. A detailed list of AI providers and applicable Data Processing Addendum terms is available under NDA upon request as part of vendor due diligence.
Data Privacy
Customer data is never sold or shared with third parties for marketing or commercial purposes. Borrower entity document PDFs are retained for 180 days by default and reports for 360 days. Customers may request shorter retention periods and deletion of their data, subject to contractual retention obligations and legal-hold requirements.
Access Control
Access to customer data is limited to authorized EntityScan personnel and the customer's authorized users, for authorized purposes only. Customer environments are logically isolated through application-level and cloud-level controls.
Infrastructure
EntityScan AI is built on Microsoft cloud infrastructure. It is hosted on Microsoft Azure, customer data is stored in Microsoft Dataverse, and the application runs on multiple application servers hosted in at least two US-based Azure datacenter regions.
Policies
We are currently working with experts to put together our company policies. Please contact us for more details.
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
Incident Response
We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
BC/DR
We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster.
Training
We provide security awareness training to all employees to ensure that they are aware of security best practices.
Change Management
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.
Physical & Environment
We have physical and environmental controls in place to ensure that our data centers are secure and reliable.
Continuous Monitoring
We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.

