generated: '2026-08-09' method: searched source: >- https://www.closinglock.com/closinglock-announces-soc2-type2-certification/ , https://www.closinglock.com/fincen-compliance/ , https://www.closinglock.com/secure-platform/ , https://www.closinglock.com/.well-known/security.txt scope: >- Closinglock publishes no API contract, so no API-level standards conformance (OpenAPI, OAuth 2.0, RFC 9457, pagination, idempotency) can be asserted from a spec. What follows is the organizational and sector compliance posture the company publishes on its own surface, plus the transport/DNS controls we probed directly. Nothing here is inferred from a specification. standards: - id: soc2-type2 name: SOC 2 Type II (AICPA / SSAE 18) conforms: true category: organizational-audit evidence: url: https://www.closinglock.com/closinglock-announces-soc2-type2-certification/ http_status: 200 published: '2023-08-22' quote: >- Closinglock announced SOC 2 Type II certification, an independent third-party audit conducted in accordance with American Institute of Certified Public Accountants (AICPA) standards for SOC for Service Organizations, also known as SSAE 18. gaps: - Auditor is not named in the announcement. - The audit period covered is not stated. - No report request flow, trust center, or attestation letter is published (see trust-center note below). - id: alta-best-practices name: ALTA Best Practices (American Land Title Association) conforms: partial category: sector-practice evidence: url: https://www.closinglock.com/secure-platform/ http_status: 200 quote: >- The platform is marketed as supporting title agents in meeting ALTA Best Practices compliance. This is a claim of support for customers' obligations, not a certification Closinglock itself holds. - id: fincen-rre name: FinCEN Residential Real Estate Rule (anti-money-laundering reporting) conforms: partial category: regulatory-enablement evidence: url: https://www.closinglock.com/fincen-compliance/ http_status: 200 quote: >- Closinglock publishes a FinCEN Compliance product page covering the anti-money-laundering reporting obligations its title-company customers carry. Again this is enablement of a customer obligation, not a Closinglock certification. - id: rfc9116-security-txt name: RFC 9116 (security.txt) conforms: partial category: transport-and-disclosure evidence: url: https://www.closinglock.com/.well-known/security.txt http_status: 200 note: >- Well-formed file served from all three reachable hosts, but the Expires field (2025-12-31T23:59:00Z) has passed, which RFC 9116 treats as stale, and no Policy field is present. - id: hsts name: HTTP Strict Transport Security (RFC 6797) conforms: true category: transport-and-disclosure evidence: source: security/closinglock-domain-security.yml note: 'TLS 1.3 with HSTS max-age=15552000 on www.closinglock.com.' - id: dnssec name: DNSSEC conforms: true category: transport-and-disclosure evidence: source: security/closinglock-domain-security.yml note: closinglock.com is DNSSEC-signed. - id: dmarc name: DMARC (RFC 7489) conforms: true category: transport-and-disclosure evidence: source: security/closinglock-domain-security.yml note: 'DMARC published with p=reject; SPF present.' - id: caa name: CAA (RFC 8659) conforms: false category: transport-and-disclosure evidence: source: security/closinglock-domain-security.yml note: No CAA records published for closinglock.com. not_assessed: - id: openapi reason: No OpenAPI or Swagger document is published on any Closinglock host. - id: oauth2 reason: >- No Closinglock authorization server was found. The OAuth/OIDC metadata served at trust.closinglock.com/.well-known/* belongs to SafeBase (issuer https://app.safebase.io/api/mcp), the trust-center vendor, not to Closinglock. - id: rfc9457 reason: No public error contract or API reference to derive problem types from. - id: iso-27001 reason: No ISO 27001 claim found on any Closinglock surface. - id: pci-dss reason: >- Closinglock moves funds (SecurePay) but publishes no PCI DSS attestation or scope statement on its public site. trust_center: published: false detail: >- trust.closinglock.com resolves and is wired to SafeBase — the host serves SafeBase's /.well-known/openid-configuration, /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource — but the trust center itself is not published: the root and every path we tried return SafeBase's 404 page. evidence: - url: https://trust.closinglock.com/ status: 404 - url: https://trust.closinglock.com/.well-known/oauth-protected-resource status: 200