Security
Last updated: August 3, 2026
How We Think About It
You send us deal documents, financial detail, and property information. Protecting that is part of the job, not an afterthought. This page describes the practices behind this website and the client portal in plain terms, and what we ask of you in return.
Encryption in Transit
This website and the client portal are served exclusively over HTTPS. Information you submit is encrypted in transit using Transport Layer Security (TLS). The site is served with HTTP Strict Transport Security, so browsers that have visited once will refuse to connect over an unencrypted channel.
Access Control in the Client Portal
The portal is built so that an account sees only what it is entitled to see:
- Every request to our systems is authenticated. Your role and account status are verified on our servers at the start of each session; they are never taken from your browser.
- Access to an individual transaction is governed by an explicit authorization record. Holding a particular role is not by itself enough to open a file.
- What each role can see is limited at the server. Capital partner accounts receive anonymized opportunity detail and do not receive borrower identity or a full street address unless disclosure is authorized.
- Staff actions that change access, such as granting or revoking visibility into a transaction or suspending an account, require explicit confirmation before they take effect. Documents released to a portal user are recorded against the staff member who released them.
Documents
Documents released to you in the portal are not served from public links. Each download is issued as a signed link that is generated on request, tied to your authenticated session, and expires after a short period. Uploads are accepted only inside a transaction your account already has access to, and are scoped to that transaction. Sharing a download link with someone else does not grant them access, and the link stops working once it expires.
Accounts and Sign-In
Portal accounts are created by 1st Private Capital, Inc.; the site does not open accounts automatically from a web form. Sign-in is available by one-time email link, by emailed code, or by password. One-time links and codes are single-use and expire shortly after they are issued. Sessions are held in your browser and refresh automatically while you are active. Signing out ends the session.
Public Forms
Inquiry forms on the public site are rate limited and carry automated-submission protection. When you submit an inquiry, our server records the originating IP address and browser user-agent string to support those protections and to investigate suspected fraud. Public forms are intentionally limited to contact and transaction detail; they are not a channel for sensitive identifiers.
Retention and Handling
Transaction records and documents are retained for as long as needed to provide our services and thereafter as required by our legal, tax, audit, and recordkeeping obligations. Access to loan file material inside the company is limited to personnel who need it for the transaction. Our Privacy Policy describes what we collect and how it is used and disclosed.
What We Ask of You
- Do not include full account numbers, Social Security numbers, or other government identification numbers in general contact forms. When documents are required for a loan file, we will tell you directly how to deliver them.
- Use a strong, unique password if you sign in with one, and do not reuse it on other sites.
- Do not forward sign-in links or codes. Anyone holding one can use it.
- Sign out when you are finished on a shared or public computer.
- Tell us immediately if you believe your account has been accessed without authorization.
Wire Fraud and Impersonation
Real estate transactions are a standing target for wire fraud. Criminals monitor transactions, imitate the parties involved, and send altered payment instructions at exactly the moment they are expected.
- Treat any emailed wire instruction, or any change to instructions you already have, as suspect until you verify it.
- Verify by calling a number you already know to be ours, such as the number published on our contact page. Never call a number contained in the message you are trying to verify.
- We will not ask you for your portal password, and we will not ask you to disclose a one-time sign-in code.
- Be skeptical of urgency. Pressure to act before you can verify is itself a warning sign.
If something feels wrong, stop and call us before you send anything.
Reporting a Security Concern
If you believe you have found a security issue involving this website or the client portal, tell us and we will look into it. Please include enough detail to reproduce the issue and give us a reasonable opportunity to address it before disclosing it publicly. We ask that testing stay within your own account and stop short of accessing other users' data, degrading service, or modifying information.
- Email: info@1stPrivateCapital.com
- Telephone: (323) 304-4978
You can also reach us through the contact page.
No Guarantee
No website, transmission method, or storage system is completely secure. The practices described here reduce risk; they cannot eliminate it, and nothing on this page is a warranty or guarantee of security.