Mortgage education
Sharing Mortgage Documents Securely With Your Lender
A loan file carries your Social Security number, your date of birth, and an account number for everything you disclosed. Federal rules require the companies handling it to encrypt that material in transit. Here is how to hold up your end of the exchange, and how to check that a request is genuine before you answer it.

The short answer: the portal, not the inbox.
Send them through your lender's own secure portal, not as email attachments. Federal rules require the companies handling your loan file to protect customer information by encryption in transit, and a portal is how that happens. Before you upload anything, confirm the request came from the licensed person on your file.
Underwriting runs on paper. Over the weeks between application and closing you will be asked for pay stubs, W-2s, bank statements, tax returns, a driver's license, sometimes a divorce decree or a death certificate. The requests arrive in bursts, often with a deadline attached, and the fastest thing to do is almost always the wrong thing: reply to the email with the file attached.
This article is about the boring mechanics of moving those documents safely, who is required to protect them once they arrive, and how to tell a real request from a convincing imitation. It is general education, not legal or security advice for your specific situation.
What is actually in a mortgage file.
It helps to be precise about what you are handing over, because the phrase “financial documents” undersells it. A complete loan file usually contains your full legal name and current address, your Social Security number, your date of birth, your employer and income history, and account numbers for every bank, retirement, and credit account you disclosed. Two months of bank statements alone can show where you shop, where you bank, and roughly what your balance looks like on any given day.
Federal rules have a name for that material. The Safeguards Rule defines it this way:
“Customer information means any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form, that is handled or maintained by or on behalf of you or your affiliates.”
16 CFR 314.2(d), retrieved August 24, 2026
Note the last clause. The obligation follows the record to anyone handling it on the company's behalf, which by closing day includes the lender, the title agency, and the settlement agent. That is a wider circle than most buyers picture, and it is a good reason to keep the number of copies you personally create as small as you can.
The rule that requires your file to be encrypted.
Nonbank mortgage companies are not free to handle this material however they like. The Federal Trade Commission's Safeguards Rule covers them by name. The agency's own guidance for businesses puts the scope plainly:
“Section 314.2(h) of the Rule lists 13 examples of the kinds of entities that are financial institutions under the Rule, including mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisors that aren't required to register with the SEC.”
Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know, retrieved August 24, 2026
What the rule then requires is the part worth knowing as a borrower, because it explains why a portal exists at all:
“Protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest.”
16 CFR 314.4(c)(3), retrieved August 24, 2026
The same subsection also requires multi-factor authentication for anyone reaching the systems that hold your information, unless the company's designated Qualified Individual has approved something equivalent or stronger in writing. So when a portal asks you to enter a code from your phone on top of your password, that is the rule working rather than the lender being difficult.
One honest caveat. These are obligations placed on the company, and they say nothing about the security of your side of the exchange. Encryption in transit protects the file while it moves through the portal. It does nothing for the copy sitting in your sent folder because you emailed it first.
Why email is the weak point.
Ordinary email is not encrypted end to end. A message may travel between well-configured mail servers over an encrypted connection, but it lands in readable form at both ends and often at several points in between, and it stays there. A pay stub emailed in March is still in your sent folder in September, still in the recipient's inbox, and still in whatever backup either provider keeps.
That persistence is what makes a mailbox worth attacking. Someone who gets into an email account does not find one document; they find the entire transaction, including the names of everyone involved, the closing date, and the language each party uses. That is the raw material for a convincing message asking you to send money somewhere new. The Consumer Financial Protection Bureau flags the risk directly in its walkthrough of the closing phase, telling buyers to be on alert for mortgage closing scams at exactly the point when documents and instructions are flying back and forth.
None of which means email is useless. It is a reasonable way to ask a question, schedule a call, or confirm that you uploaded something. Keep the account numbers and the identity documents out of it.
Verifying that the request came from your loan officer.
The strongest habit you can build costs about ninety seconds: verify a request through a channel you established yourself, not one supplied by the message.
Start with identity. Every licensed mortgage loan originator carries a unique NMLS identifier, and anyone can look it up. NMLS Consumer Access takes a name, company, or NMLS ID and returns the license record behind it. If the person emailing you is who they say they are, the number in their signature will resolve to them. If there is no number in the signature at all, that is worth a question by itself.
Then confirm the request itself by calling the number you already had, from the business card, the signed disclosure packet, or the company's published contact page. Do not use the number in the email you are checking, and do not reply to the message to ask whether it is genuine. A message written by someone who controls the mailbox will happily confirm itself.
Apply the same rule to anything that changes. A new upload link, a different email domain, a switch from the portal to an attachment, a revised set of wiring instructions: treat every one of those as unverified until a voice on a known number confirms it. Knowing which party handles which step makes it much easier to notice when a request arrives from the wrong direction.
What a real document request looks like.
Legitimate requests are specific and boring. Underwriting asks for the June and July statements for a named account, all pages including the blank ones, because the statement itself says “page 1 of 6” and the file has to be complete. It asks for the most recent two pay stubs. It asks you to explain a deposit that does not match your payroll. It points you at the portal you already logged into.
What a real request does not do is ask for the credential rather than the document. Your lender needs the bank statement, not your online banking password. It needs the account number that appears on the statement, not a photograph of your debit card. And no legitimate part of the process involves wiring money to an account first named in an email, however well the message imitates the title company. Getting your paperwork together early, with the document and question checklist in hand before the first lender conversation, cuts down on the rushed requests where mistakes happen.
A few practical habits that make the whole exchange tidier:
- Upload complete documents the first time, including pages that look blank, so the same request does not come back twice.
- Keep the files on a device with a screen lock and a current operating system rather than on a shared or public computer.
- Use a distinct, strong password for the portal and for the email account tied to it, and turn on multi-factor authentication for both.
- Avoid uploading over public wi-fi you do not control when the alternative is waiting an hour.
- Delete the working copies you made for scanning once the file has been accepted.
If you already sent something the wrong way.
Most people reading this have already emailed a pay stub at some point. That is not a catastrophe, and it does not need to become one.
Tell your loan officer and the title company directly, on a call, so the transaction is flagged and everyone treats later instructions with more suspicion. Change the password on the mailbox you sent it from and turn on multi-factor authentication there. Check that account for forwarding rules you did not create, which is a common way a compromise stays quiet. If account numbers were exposed, call the institution that issued the account and ask what it recommends.
If you believe your information has actually been misused, the Federal Trade Commission runs IdentityTheft.gov, which produces a recovery plan and the affidavit most institutions will ask for. It is better to report it while the details are still incomplete than to wait until you can describe exactly what happened.
Official sources.
Every claim above traces to a primary source, each of which was opened and read on August 24, 2026.
- 16 CFR 314.2, definitions of customer information and financial institution under the Safeguards Rule.
- 16 CFR 314.4, the required safeguards, including encryption in transit and at rest and multi-factor authentication.
- Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know, for the list of covered entities.
- Consumer Financial Protection Bureau, Owning a Home: Close, page last modified November 3, 2025.
- NMLS Consumer Access, the public license lookup maintained by the Conference of State Bank Supervisors.
For where the charges in your file show up in writing, see which Loan Estimate services you can shop for, and the guide to Texas closing costs.
