Platform Terms of Service
Version 1.0 draft · August 23, 2026
Draft — under legal review. This baseline is published while counsel review is in progress, so that it can be read rather than withheld. It may change. It does not alter any signed agreement — where an executed master agreement and this page differ, the agreement governs in full (§1).
These terms govern use of the Apsis Line platform — the licensed software, not this website. For terms covering the public website, see Terms of Use.
1. A signed agreement takes precedence
Apsis Line is licensed to financial institutions under a written master agreement. Where a signed agreement and this page differ, the signed agreement governs in full. These terms are the published baseline for matters an agreement does not address; nothing here amends, supplements, or waives any executed contract.
2. What the platform is — and is not
Apsis Line is a mortgage point-of-sale (POS) platform. It is not a loan origination system (LOS): the institution’s LOS remains the system of record, and the platform pushes loans to it and orders services through its application programming interfaces (APIs). Apsis Line is not a lender, broker, or loan originator, and it makes no credit decisions. Regulated disclosure packages and their timing obligations stay with the system of record; the platform orchestrates the trigger.
3. The relationship: you are the financial institution
The institution is the financial institution with the consumer relationship. Apsis Line acts as a service provider processing borrower data on the institution’s instructions, and does not use borrower personal information for its own purposes.
Under the Gramm-Leach-Bliley Act (GLBA) and Regulation P, notification duties to consumers and regulators are the institution’s. Apsis Line’s undertaking is to notify the institution so it can meet them — see §6. Apsis Line will not action a borrower’s deletion or access request received directly; it routes the request to the institution, because a record the institution is legally required to retain must not be destroyed on a service provider’s initiative.
4. Data ownership
The institution owns its data. Borrower data, journey state, and the audit ledger belong to the institution and are held in that institution’s own isolated deployment — its own application, its own database, its own credentials. No institution’s data shares a runtime, a database, or a key space with another’s.
The one exception is stated plainly rather than buried: a deny-by-default, auditable export of de-identified, tenant-anonymous structural aggregates — carrying no borrower personal information and no per-institution identity — may be used for new-deployment cold-start priors and benchmarking. The exportable shapes are an explicit allowlist the institution can inspect, and the export can be disabled.
5. Security commitments
Vendor credentials are held server-side and never reach a browser. Deployments are isolated per institution. Records in the audit ledger are append-only. Where a control cannot be evaluated, the platform refuses rather than proceeds. A simulated vendor connection is always labeled as simulated and never presented as live. The current posture, including what is not yet built, is on the Security page.
6. Security-incident notification
If Apsis Line confirms a security incident affecting the institution’s data, the institution receives written notice within two business days of confirmation, to the security contact designated at onboarding. The clock starts at confirmation, not at first suspicion, and that is stated rather than left ambiguous.
7. Availability
Availability commitments, maintenance windows, and any service credits are set in the institution’s signed agreement. This page does not create a service-level guarantee. Planned maintenance is communicated through the institution’s named contact.
8. Acceptable use
Do not attempt to access another institution’s data; probe, scan, or test the platform’s security without written authorization; reverse engineer the platform except where that right cannot lawfully be excluded; or submit unlawful content or data the institution has no right to process. Institution staff accounts are individual — shared logins defeat the audit trail that protects both parties.
9. Confidentiality
Each party protects the other’s confidential information and uses it only to perform under the agreement. Borrower personal information is confidential without qualification and survives termination indefinitely.
10. Term, termination, and exit
Term and termination rights are set in the signed agreement. On termination, the institution may export its data in a documented format, and Apsis Line deletes or returns remaining copies on the timetable that agreement sets, subject to any retention the institution directs or the law requires. Exit is a contractual right, not a courtesy.
11. Intellectual property
Big Head Consulting retains all rights in the Apsis Line platform, its software, and its documentation. The institution receives the license its agreement grants and no more. The institution retains all rights in its own data and its own marks. Third-party names and marks belong to their owners; references describe technical interoperability only and imply no endorsement or affiliation.
12. Warranties and liability
Warranties, disclaimers, indemnities, and limits of liability are set in the signed agreement. Absent one, the platform is provided “as is” to the maximum extent permitted by law.
13. Changes
These baseline terms may be updated; the version and date above reflect the current text. A change here never alters a signed agreement. Material changes affecting licensed institutions are communicated through their named contact.
14. Contact
Questions about these terms: robert@apsisline.com. For support, see Support.