Incident Response Commitment

How LoanBot AI responds to security incidents

This is a public summary of LoanBot AI's incident response requirements. Detailed contacts, evidence locations, credentials, and investigative procedures are restricted and maintained separately. This page does not claim use of security tools, staffing, backup systems, recovery times, or exercises that have not been verified.

Version 1.1Effective August 18, 2026
Report promptly. Suspected unauthorized access, credential exposure, data disclosure, destructive activity, malware, lost privileged devices, or material service disruption should be reported immediately through the security contact in the applicable agreement or the authenticated LoanBot support channel. Do not include prohibited borrower information in the report.
1

Identify and triage

LoanBot opens an incident record, records discovery facts, assigns responsible leads, preserves available evidence, and evaluates whether restricted data, PMR, customers, credentials, or critical services may be affected.

2

Contain

Actions may include suspending accounts, invalidating sessions and tokens, rotating credentials, disabling integrations or features, restricting public access, isolating affected devices, and preserving a known-good rollback point.

3

Investigate and eradicate

LoanBot determines the affected systems and time period, removes unauthorized access or configuration, patches the underlying weakness, reviews related accounts and data paths, and coordinates with providers and advisors as appropriate.

4

Assess impact and notify

LoanBot evaluates affected data, individuals, customers, systems, jurisdictions, encryption, provider involvement, and legal or contractual duties. Preliminary facts are identified as preliminary; LoanBot does not delay escalation solely because the full investigation is incomplete.

5

Recover and validate

Service is restored from a known-good state or through provider-supported recovery. Authentication, authorization, data integrity, restricted-data projections, secrets, integrations, and monitoring are validated before higher-risk functions return to service.

6

Learn and improve

Material incidents receive a post-incident review documenting timeline, root cause, impact, control performance, notifications, corrective actions, owners, target dates, and validation or retest results.

PMR notification

When an incident may reasonably affect PMR data, users, customers, integrations, availability, or a control relied upon by PMR, LoanBot escalates the event internally and provides PMR notice without unreasonable delay. LoanBot's internal target is initial notice no later than 24 hours after discovery of a confirmed or reasonably suspected PMR-impacting incident, unless the governing agreement requires a shorter period.

Initial notice may be preliminary and, to the extent known, identifies the incident, discovery timing, affected services or data, operational impact, containment, current status, LoanBot incident contact, and next-update timing. Material updates and a final report are provided as appropriate to the event and agreement.

Testing and evidence

LoanBot requires documented incident-response exercises and tracks corrective actions to closure. An exercise is not represented as complete until a dated report identifies the scenario, participants, decisions, findings, owners, and retest status.