Skip to content
NexusMortgageOS

Integrations

Vendor network & who contracts what

NexusMortgageOS ships the integrations. Each mortgage company brings its own vendor accounts and seals them in a private, encrypted vault — so nobody's credentials, pricing or data are ever shared across companies.

Integration categories

10

credit through billing

Credential isolation

Per tenant

AES-GCM sealed

Vendor markup

$0

we never resell data

Pre-go-live checks

Automated

nightly re-verification

How a vendor gets connected

Four steps, no engineering work on your side

1. You contract the vendor

Sign directly with your credit reseller, AUS, e-sign and AMC providers. You keep your negotiated pricing and existing relationships — we don't resell or mark up vendor data.

2. Seal the credential

An admin pastes the API key, integration key or account ID into the Integrations Hub. It's encrypted with AES-GCM against your tenant and is never readable in plain text, including by us.

3. Verify before go-live

The verification harness runs a scripted, non-PII golden-path order against each credential and asserts the response contains the fields the platform needs. The readiness board turns green only when it passes.

4. Order from inside the loan file

Credit, AUS, appraisal, VOA and e-sign orders fire from the loan file. Every order and response is written to the immutable audit ledger with the ordering user attached.

Integration catalog

Lender-contracted vendors vs. what's included in your subscription

CategoryVendorsWhere it's usedContracted by
Credit reportsXactus (Universal Credit), plus any bureau reseller with a REST APITri-merge and soft pulls at intake, re-pulls before CTC
Requires your own reseller agreement and permissible-purpose attestation.
Lender
Automated underwritingFannie Mae Desktop Underwriter (DU), Freddie Mac Loan Product Advisor (LPA)Casefile submission, findings ingestion, condition auto-mapping
Your seller/servicer or sponsored originator credentials.
Lender
E-signatureDocuSign, SnapdocsDisclosure packages, closing packages, eNote-ready envelopes
Integration key + account GUID from your own DocuSign org.
Lender
Document preparationDocMagicTRID-compliant LE/CD, state-specific closing packages
Plan codes are tied to your doc-prep account.
Lender
Appraisal / AMCReggora, Clear Capital and equivalent AMC APIsOrder placement, status tracking, UCDP delivery
AMC panel and fee schedule stay under your agreement.
Lender
Asset & income verificationPlaid (VOA), payroll verification providersBank asset reports, deposit analysis, direct-source income
Your Plaid client ID and secret; borrower consent captured in-app.
Lender
Flood determinationLife-of-loan flood determination providersDetermination at disclosure, monitoring after close
Ordered per file against your account.
Lender
Messaging & emailTwilio (SMS/voice), Resend (transactional email)Borrower nudges, milestone alerts, disclosure notifications
Included in your subscription; opt-out registry enforced platform-wide.
Platform
AI modelsPlatform-hosted model gatewayDocument classification, condition drafting, borrower Q&A
Included. Your data is never used to train third-party public models.
Platform
BillingStripeSubscription and onboarding invoices
Billing data only — no borrower data reaches the processor.
Platform

Don't see your vendor? Any provider with a documented REST API can be added to the integration layer — tell us which one during onboarding.

What to gather before onboarding

Have these ready and go-live takes days, not weeks

VendorCredentials needed
Credit reseller (e.g. Xactus)Account ID, username, password/API key, permissible-purpose attestation
Fannie Mae DUSeller/servicer number, DU user ID and password
Freddie Mac LPASeller number, LPA user ID and password
DocuSignIntegration key, account GUID, RSA private key or secret
DocMagicCustomer ID, user name, password, plan codes
AMC / appraisalAPI key and client ID from your AMC
PlaidClient ID and secret (production environment)

Security of vendor credentials

Why your compliance team can sign off

  • Credentials are encrypted with AES-GCM before they touch the database; only the last four characters are stored in readable form for identification.
  • Decryption happens only inside a server function, at the moment an order is placed, and the plain value is never returned to the browser.
  • Row-level security binds every credential row to your tenant — no other company, and no other tenant admin, can read or use it.
  • Rotation is one click; the previous value is destroyed, not archived.
  • Every order and verification is written to the append-only audit ledger with the acting user, timestamp and outcome.