TITLEDOC AI · PLATFORM OVERVIEW
Licensing, Access Control & Security — Built for the Way Title Money Moves
TitleDoc AI is a unified platform for title agents and underwriters. Because our customers safeguard escrow funds and issue regulated instruments, the platform's commercial model, its role-based access controls, and its security architecture were designed together — around one rule: the controls that protect client funds are never optional, never an upgrade, and never an afterthought.
LICENSING STRUCTURE
Simple editions. Fair seats. No surprises.
Two portals, two models — because agents and underwriters create value differently. Agents license by organization size and the people doing production work. Underwriters license by the size of the agency network they monitor.
Title Agent editions
Single-branch agencies
The complete production platform — search through policy issuance — for independent, single-office agencies.
- Full order-to-policy workflow with AI examination
- Every role, every control, one branch
- Included monthly AI examination allowance
Multi-branch agencies
Adds the management layer for agencies operating several offices under one roof.
- Regional Manager role & cross-branch reporting
- Centralized examination queues
- Audit & ALTA Best Practices evidence module
Multi-region operations
For the largest agencies, with enterprise identity and isolation options.
- Single sign-on (SSO) & automated user provisioning
- Dedicated database isolation & customer-managed keys
- API access and named support
Seats priced by the work, not the headcount
Seats are licensed by role class, so an agency pays production rates only for production work — and assistants are deliberately inexpensive, because the platform's draft-and-release workflow is designed to let assistants prepare and officers approve.
| Seat class | Covers | Pricing approach |
|---|---|---|
| Production | Escrow Officers, Examiners, Post-Closing | Standard seat rate — the anchor |
| Assistant | Escrow Assistants | A fraction of production — leverage should never be rationed |
| Back-office | Accounting, Business Development | Mid-tier |
| Management | Branch & Regional Managers | Mid-tier, with included seats as your team grows |
| Oversight | Executive, Compliance, System Admin | Always free, always unlimited |
Oversight seats are free at every edition because we never want a seat fee standing between an agency and its own control environment. Usage-based pricing applies only to AI production actions (like AI title examinations), with a monthly allowance included in every edition — and reviewing, verifying, or auditing AI output is never metered. There are no per-closed-file platform fees.
Underwriter editions
Underwriter licensing scales with the size of the appointed-agency network you monitor — not your headcount, so staffing your claims and agency-management teams properly never costs more. Each edition includes everything in the tier before it.
| Edition | Agency network | Includes |
|---|---|---|
| Core | Up to 25 appointed agencies | CPL, jacket & policy registers · remittance reconciliation · full claims administration with tiered authority · appointment management |
| Standard | Up to 150 | Core, plus the agency audit program — scheduling, scoped audit-packet access, findings & remediation tracking — and delinquent-remittance worklists |
| Premium | Up to 500 | Standard, plus the continuous monitoring engine: agency scorecards, issuance-anomaly detection, void-rate deviation alerts, CPL-without-policy tracking, and network-wide remittance delta analysis |
| National | Unlimited | Premium, plus enterprise SSO & automated provisioning, dedicated isolation & customer-managed keys, API access, multi-entity support for affiliated underwriters, and named support |
Two commitments hold at every underwriter edition: claims administration is always included — an underwriter can't function on-platform without it — and critical fraud-pattern alerts are delivered to every edition. We will never withhold a fraud signal as an upsell, and we will never degrade monitoring as a collections tactic.
Never license-gated, at any tier
Multi-factor authentication · dual-control approval chains · segregation-of-duties enforcement · immutable audit logging · wire-verification controls · the fraud response fast path · trust account reconciliation · oversight roles. If it protects client funds, it's in every edition — permanently.
Transparent commercial commitments
Sandbox & Pilot
A free sandbox with synthetic data for evaluation, and a time-boxed pilot license for running real files — with conversion pricing locked up front, so going live is a signature, not a renegotiation.
Signed quotes, reconciled invoices
Every subscription begins with an e-signed order form, and every subsequent change is a signed amendment or a catalog action under your existing terms. Every invoice line reconciles to signed paper.
Your data, guaranteed
If a subscription lapses, the platform degrades to read-only — reconciliation, compliance reports, and full data export remain available. We publish our export format. Fiduciary records are never held hostage.
ROLE-BASED ACCESS CONTROL
The role model IS the control environment
Most title systems treat roles as menu visibility. TitleDoc AI treats them as what your underwriter auditor actually tests: segregation of duties around trust funds, enforced by the system rather than by policy memo.
Purpose-built roles, not a toggle
The agent portal ships eleven distinct roles — from Escrow Officer and Examiner to Accounting (itself split into reconciliation and release functions held by different people), Compliance, and a System Administrator who can configure everything and read nothing. The underwriter portal ships eight, including tiered claims authority and a read-only auditor. Every role combines WHAT a person can do with WHERE they can do it — assigned files, branch, region, or company — so a 200-person agency's access map matches its org chart automatically.
Draft and release
Junior staff prepare; senior staff approve. Assistants draft settlement statements, receipts, and protection letters that an officer releases — full productivity without expanding money-touching access.
Dual control on every dollar
No single user — including the CEO — can both initiate and release a disbursement, or enter and approve changed wire instructions. Wire changes require a second approver plus a recorded out-of-band callback before the approve button unlocks. Disbursement authority tiers with dollar exposure. Executives hold no transactional authority at all — by design, which removes the most-targeted accounts from the fraud surface entirely.
Structurally enforced separation
The platform refuses to assign conflicting duties to one account: the person who reconciles a trust account can never release funds from it; the person who enters wire instructions can never approve them; IT administrators can never open escrow data. These aren't guidelines — role assignment validates against them in real time.
01
Immutable audit trail
Every action, approval, export, and sensitive-data view is logged append-only — who, what, when, before and after — readable by Compliance and Executive, writable by no one.
02
Statement-matched disbursements
Closing funds move only against a line on the finalized settlement statement — exact payee, exact amount — and no file can ever disburse beyond its own collected balance.
03
Accountable exceptions
Coverage gaps happen. Break-glass access is manager-approved, reason-coded, auto-expiring, and lands on the compliance review queue — so nobody ever needs to share a password.
04
Audit-ready by default
Compliance reporting — exception digests, wire-control logs, ALTA Best Practices evidence — is generated from the same system of record your team works in daily.
SECURITY ARCHITECTURE
Isolated by architecture, encrypted everywhere, transparent always
TitleDoc AI runs as two independent multi-tenant portals — one for agents, one for underwriters — governed by a separate administrative control plane. Three planes, three authentication realms, one principle: your data is yours.
MULTI-TENANCY
Isolation enforced in the database
- Every tenant's data segregated with database-level row security — deny by default, so isolation holds even against application defects
- Agent and underwriter portals never share sessions, credentials, or authentication realms
- Dedicated database isolation available at the enterprise tier
- Automated isolation testing runs on every release — cross-tenant access attempts must fail before software ships
ENCRYPTION
At rest and in transit
- All traffic encrypted in transit with modern TLS (1.2+)
- All data encrypted at rest with AES-256, including documents and backups
- Per-tenant encryption keys — one tenant's key never protects another's data
- Customer-managed keys (CMK) available at the enterprise tier
IDENTITY
Strong authentication, everywhere
- Multi-factor authentication mandatory for every user at every tier
- Step-up verification for wire approvals, bulk exports, and permission changes
- Enterprise SSO (SAML/OIDC) with automated provisioning — deactivate a user in your directory, and their access ends here too
- Session timeouts on screens displaying account or wire data
OUR ACCESS TO YOUR DATA
None — unless you grant it
- Platform staff cannot open your files, ledgers, or client records — structurally, not just by policy
- Support access requires your approval: scoped, time-boxed, and auto-expiring
- Every support session is logged in YOUR audit trail — your dashboard shows exactly who was in your environment, when, and what they viewed
- No advertising use of your data, ever; your data trains no shared models
DATA EXCHANGE
A controlled bridge between counterparties
- Agents and underwriters exchange data only through signed, appointment-scoped events — an underwriter sees activity on its own paper, never your escrow ledgers, other underwriters' policies, or your client relationships
- Underwriter audit access is granted by you, scoped to the request, time-boxed, and logged on both sides
- Wire instructions, bank details, and trust ledger detail never cross the boundary
RESILIENCE & RECORDS
Fiduciary-grade record keeping
- Append-only trust ledger — entries are corrected by reversal, never edited or deleted
- Issued instruments are immutable, with provable lineage to the exact form version used
- Records retained per state requirements, with certificates of destruction after lawful retention lapses
- Encrypted backups inherit each tenant's keys
Built for the threat that matters most in this industry
Wire fraud and escrow theft are the title industry's defining risks. TitleDoc AI's answer is layered: mandatory out-of-band verification on wire instruction changes, positive-pay integration, disbursements locked to settlement statements, hour-of-day release controls, and a system-enforced fraud response checklist that freezes funds and starts the bank-recall clock in minutes — not meetings.
Compliance alignment
The platform is designed around ALTA Best Practices — trust accounting with daily three-way reconciliation, information security, and consumer-protection controls — and around state regulatory regimes, beginning with Texas promulgated forms, rates, and procedural rules, each verified against the current regulator publication before activation. Statutory claim-handling timers are built into the workflow with visible countdowns, and compliance reporting is generated from the operational system of record, so audit preparation is a report run, not a fire drill.
This overview describes the TitleDoc AI platform's design commitments. Capabilities noted as enterprise-tier require the corresponding edition. For a detailed security review, architecture documentation, or a copy of our data-handling commitments for your vendor-diligence process, contact our team.