Loopenta
Checking your invite...
Just a moment.
Invite Expired or Invalid
This invite link has expired or already been used.
Contact your admin for a new invite.
Account Created!
Your password has been set. You're ready to start prospecting.
Terms of Service & User Agreement
Please read and accept before continuing
LMI PROSPECT FINDER / LOOPENTA TERMS OF SERVICE AND USER AGREEMENT Version 1.0 1. ACCEPTANCE OF TERMS By accessing or using Loopenta ("the Platform"), you agree to be bound by these Terms of Service. If you do not agree, do not use the Platform. 2. AUTHORIZED USE The Platform is licensed for use by authorized mortgage professionals and financial institution employees only. You may not share your credentials or permit unauthorized access. 3. DATA PRIVACY AND CONFIDENTIALITY You agree to handle all borrower and customer data in accordance with applicable federal and state privacy laws including GLBA, CCPA, and your institution's data policies. 4. CUSTOMER INFORMATION You acknowledge that customer PII entered into the Platform is transmitted over encrypted connections (TLS) and stored in access-controlled, tenant-isolated cloud infrastructure with encryption at rest provided by our datastore. You are responsible for obtaining proper consent from customers before entering their information. 5. INTELLECTUAL PROPERTY The Platform, including all features, designs, and content, is the exclusive property of Loopenta. Unauthorized reproduction or distribution is prohibited. 6. ACCEPTABLE USE You agree not to use the Platform for any unlawful purpose, to misrepresent data, or to violate any applicable mortgage lending regulations including RESPA, ECOA, and CRA guidelines. 7. TERMINATION Access may be terminated at any time for violation of these terms. All data will be retained per applicable regulations. 8. LIMITATION OF LIABILITY The Platform is provided "as is." We are not liable for any damages arising from your use of the Platform. 9. GOVERNING LAW These terms are governed by the laws of the State of California. 10. CONTACT Questions: admin@lmitool.com By typing your name and clicking "I Agree," you are providing a legally binding digital signature confirming you have read, understood, and agree to these terms.
Loopenta
Built by a mortgage pro · One platform, four sides

Every deal has four sides.Now they finally share one loop.

Finally, a CRM that connects your entire transaction ecosystem without the usual security tradeoffs. Whether it's your loan team, realtors, or title partners, you set the rules for who sees what. Your data is yours alone, and information flows only with explicit client permission and strict policy adherence. Every share is automatically logged and compliance-checked, giving you peace of mind throughout the entire closing process.

Everyone in the loop by the rules you set 🏠Realtor 🏦Loan Advisor 📜Title & Escrow 🛡️Leadership
Welcome back
Sign in to your workspace.
Forgot password?
Built by a mortgage pro · Not by a software company

Every deal has four sides.
Now they finally share one loop.

Everyone stays in the loop — by the rules you set. The Realtor, the loan advisor, the title desk and leadership each keep their own data: your data belongs to your company, or to you; by default nothing is shared, and information moves only with your company's policy and the client's permission. Every share is logged.

Why Loopenta exists
A deal isn't a line. It's a loop.

Every deal passes through the same four hands — Realtor, loan advisor, title & escrow, leadership. Everyone can be kept in the loop — but only by the rules you set: each keeps their own data, by default nothing is shared, and information moves only with your company's policy and the client's permission. Every share is logged. Pick your side below to see how.

Everyone in the loop by the rules you set 🏠Realtor 🏦Loan Advisor 📜Title & Escrow 🛡️Leadership
Why teams pick Loopenta

The four promises the industry stopped making.

🔓
You own your data
One-tap export, always. Yours — not your brokerage's or ours.
🤝
No contracts
Month-to-month, forever. No traps, no exit fees.
✍️
AI that does the work
The follow-up is already written when it's due. Approve, send, done.
🛡️
Compliance in the DNA
Consent checked before send, records sealed after.
Request early access
We onboard in small groups so every team gets white-glove setup (it takes minutes, not weeks — but we like to be there for it).
Equal Housing Lender · NMLS-stamped outreach · Encrypted in transit (TLS) · Encryption at rest · MFA available · Tenant-isolated
Loopenta
Home
User
Navigate
Good morning, there
Here's your overview for today
Ready
Compliance posture

Loading…

Open obligations
A couple of quick wins to stay spotless.
Loading…
Recent activity
Your latest logged work, newest first.
Loading…
Property Intelligence Setup
One-time setup · Takes about 5 minutes
Note: Property Intelligence works without RapidAPI — you get assessor, HUD, HMDA, and deed data for free. RapidAPI adds Zillow enrichment (photos, Zestimates, listing agents). Free tier: 20 lookups/day.
1
Sign Up for RapidAPI
1. Go to rapidapi.com and create a free account
2. Search for "Zillow Com" API
3. Subscribe to the Basic plan (free: 20 requests/day)
2
Copy Your API Key
On your RapidAPI dashboard, find your API Key and copy it.
3
Add to Cloudflare Worker
1. Go to dash.cloudflare.com
2. Click Workers & Pages → click lmi-tool
3. Click SettingsVariables
4. Add variable:
Variable name: RAPIDAPI_KEY Value: (paste your API key)
5. Click Save and Deploy
4
Set Up KV Cache (Recommended)
1. In Cloudflare dashboard → Workers & PagesKV
2. Click Create namespace → name it LMI_PROPERTY_CACHE
3. Go to Worker Settings → VariablesKV Namespace Bindings
4. Add binding: KV_NAMESPACELMI_PROPERTY_CACHE
Free: 100,000 reads/day, 1,000 writes/day. Caches results to minimize API calls.
Need help? Email admin@lmitool.com
Property Detail
Defense Packet Preview
New Sequence
Set Goals
Setting Up SMS for Your Team
One-time setup \u00b7 Takes about 10 minutes
\uD83D\uDCA1 Estimated cost: ~$1.15/mo per MLO number + ~$0.008 per message sent. A 6-MLO team costs roughly $12/month total.
1
Create a Twilio Account
1. Go to twilio.com and sign up for a free account
2. Verify your email and phone number
3. On your Twilio dashboard, find your Account SID and Auth Token \u2014 copy both
Account SID: ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Auth Token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
2
Add Credentials to Cloudflare Worker
1. Go to dash.cloudflare.com and log in
2. Click Workers & Pages \u2192 click lmi-proxy
3. Click Settings tab \u2192 Variables
4. Click Add Variable and add these two:
Variable name: TWILIO_ACCOUNT_SID Value: (paste your Account SID) Variable name: TWILIO_AUTH_TOKEN Value: (paste your Auth Token)
5. Click Save and Deploy
3
Add SMS Routes to Your Worker
Paste this into Claude Code to update your Worker:
Update the Cloudflare Worker at lmi-proxy.aaronsimonson.workers.dev to add three SMS route handlers. The env vars TWILIO_ACCOUNT_SID and TWILIO_AUTH_TOKEN are already set in Cloudflare. Add the /sms/send, /sms/incoming, and /sms/provision routes to the existing Worker code and deploy.
4
Assign Phone Numbers
Once steps 1\u20133 are complete, come back to this screen:

1. Each MLO row below will show an "Assign Number" button
2. Enter their local area code (559 for Fresno, 213 for LA)
3. Click Find Available Numbers
4. Confirm to purchase \u2014 about $1.15/month per number
5
Connect Twilio to Your App
For each phone number you purchase in Twilio:

1. Go to Twilio \u2192 Phone Numbers \u2192 Active Numbers
2. Click the number
3. Under Messaging \u2192 "A message comes in" set:
URL: https://lmi-proxy.aaronsimonson.workers.dev/sms/incoming Method: HTTP POST
4. Click Save
5. Repeat for each MLO's number
6
Test It
1. Assign a number to yourself first
2. Open any contact record with your phone number
3. Tap Send SMS and send a test message
4. You should receive it within a few seconds
5. Reply to it \u2014 the reply should appear in your Communications inbox
\u25CB Not yet connected
Need help? Email admin@lmitool.com
New Deal
Deal
Loading...
Add Past Customer
Send SMS
📧 Send Email
📞 Log a Call
Borrower
Loading...
📥 Import Contacts

Upload a CSV file. First row must be column headers.

📄
Click to choose CSV file
or drag and drop here
Loopenta
Admin Panel
User
Navigate
0
Total Users
0
Active Users
0
Admins
✉️ Invite New User
Send an email invite — they set their own password when they click the link.
or
👥 All Users
📌 Team Saved Prospects
Loading...
📋 Team CRA Activity Log
Loading...
💳 Subscriptions & Billing
Loopenta
Super Admin
User
Navigate
All Products — Platform Management
👤 View as role Preview only · your access is unchanged
🏢 All Organizations
💳 Organization Billing
Loading RentCast status...
🧩 Fleet-wide Feature Matrix
Tenants × features. Click any cell to toggle. Disable-only: you cannot force a feature above a tenant’s tier.
Enabled Default (on) Disabled override Above tier (locked)
Loading feature matrix…
🔒 Audit Log
Immutable · All access logged
Loading...
🛡️ Security Posture
Bank-grade security rollout — statuses below were audited against the deployed app and live site on Jul 23, 2026. Five of eight controls are fully live; each remaining card lists exactly what's left.
📊 Current posture
Checking…
Loading user / posture data from Firestore…
✅ Implemented — verified live
Phase 2A — Firebase Auth migration
Live
Every user authenticates through Firebase Auth instead of the old plaintext-password comparison. New invites also go through Firebase Auth. Existing DIY users are migrated on demand.
Phase 1 — Firestore rules lockdown
Deployed
The hardened Phase-1 ruleset is live: privilege-escalation guard on /users (nobody can change their own role, org, or tier), admin-only tenant writes, append-only auditLog + agreementLog, one-shot invite acceptance, and org-scoped writes. Rules changes auto-deploy from main via deploy-rules.yml (rules PRs are excluded from auto-merge — they need a human merge). Remaining tightening is Phase 1.5: move the org-scoping of legacy "signed-in-only" collections from client filters into the rules once their queries are refactored.
Phase 6 — Security headers
Live on lmitool.com
Shipped via the repo's _headers file and verified on the live site: HSTS (preload), Content-Security-Policy, X-Frame-Options DENY, nosniff, strict referrer policy, Permissions-Policy, and Cross-Origin-Opener-Policy on every response. The check below re-verifies against this origin any time.
Phase 7 — Worker rate limiting
Live in Worker
Per-IP KV rate limits are live in worker.js on every abuse-prone endpoint: signup, auth email, consent, error-report, rates, all /mfa/* routes, and open-house sign-in (30/hr per IP + 500/day per event). Failed MFA verification locks the account for 30 minutes after 5 attempts, and admin endpoints throttle after 5 failures with a 429 + Retry-After.
Phase 2B — TOTP Multi-factor Authentication
Live — enrollment is opt-in
Built and live as our own worker-side TOTP (RFC 6238) — not Firebase's provider, so there is no Firebase-console step. Secrets are AES-GCM-encrypted in Cloudflare KV; users enroll from Settings → Security; enrolled users get a 6-digit challenge at every login (via the mfaEnabled custom claim); downloadable backup codes and a full audit trail are included. What's left is enforcement — requiring enrollment (admins first) — which is the Phase 8 prerequisite.
🟡 Partially live — remaining work listed
Phase 3 — FFIEC password policy
Core live
Live at every password entry point (sign-up, change, forced reset, admin): 12-character minimum, upper + lower + digit + symbol, can't equal your email, and a HaveIBeenPwned breach check (k-anonymity — only the first 5 chars of a local SHA-1 hash are sent; the password never leaves the browser; fails open on API outage). Still to ship: no-reuse-of-last-5 (the passwordHistory store exists in the rules but the client never writes it yet).
Phase 4 — Session hardening + lockout
Idle logout live
Live: inactivity auto-logout (default 30 min, tenant-configurable, audit-logged when it fires). Still to ship: an absolute session cap and explicit failed-login lockout counters — today brute force is covered at the API layer by Firebase Auth's native throttling plus the Worker rate limits above.
Phase 5 — Audit log completeness
Partial coverage
Live: _auditLog covers auth events (including auto-logout), the full MFA lifecycle, security-flag changes, and feature-flag flips — and the log itself is append-only per the rules. Still to do: a coverage sweep for tier changes, user promote/demote, invite revoke, CRA report generation, and data exports.
🔒 Final lockdown — blocked on prerequisites
Phase 8 — MFA-gated Firestore rules
Blocked — 3 prerequisites
The final lockdown: sensitive Firestore access requires an MFA-verified session. Blocked on three things: (1) the staged firestore.rules.final gates on firebase.sign_in_second_factor — a claim this app never mints; it must be rewritten to check the worker-minted mfaEnabled custom claim or it locks out every user including admins; (2) its collection coverage must be reconciled with the live ruleset so live collections don't fall into deny-all; (3) MFA enrollment must be enforced for all users first (see Phase 2B). Do not deploy until all three are done.
📚 Full rollout plan
Everything in this page is summarized from SECURITY_ROLLOUT.md in your repo. That file is the canonical reference if you need more detail than what's shown here.
⚙️ Platform Settings
📜 Legal — User Agreement
Agreement Log
Click to load...
🔧 Data Migration
Backfill orgId: "golden1-org" onto all existing users, OYZ entries, activities, and realtors that don't have an orgId yet.
🔐 Auth Migration — DIY → Firebase Auth
Creates a Firebase Auth account for every user in /users with their current password. After this runs, users will be prompted to set a new password on next login. Run once. Safe to re-run — already-migrated users are skipped.
🎟️ Early-Access Requests
Applications from the public learn-more page. Approving a realtor request mints a single-use invite link (14-day expiry) — copy it or open a pre-written email and send it yourself. Other roles don’t have automated invites yet; handle those by hand.
Loading…
🧪 Demo Environment
A self-contained demo tenant (org-demo-northgate) with realistic fake data for prospect walk-throughs. Safe: while logged in as the demo org, SMS and email are simulated — nothing real is ever sent. Isolated: these actions only ever touch the demo org; no other tenant's data is read or modified.
Demo logins (password set at seed time, shown in the seed log):
demo-admin@loopenta.com · demo-manager@loopenta.com · demo-hla1@loopenta.com · demo-hla2@loopenta.com · demo-hla3@loopenta.com
▶ Walk-through logins
Jump straight into any demo persona's real screens — no sign-out, no passwords. A bar appears at the bottom to hop between roles or return here. (Run Reset Demo first if a persona is missing.)
🚀 Marketing
Operationalize the go-to-market: a per-role launch checklist, the full asset library, a screenshot gallery, and live AI-discoverability status. Everything the audit produced, in one place.
Loading…
🤝 Invite a partner or future employee — one step
Fill in who, pick the walkthrough date & time, and click once: the personal NDA-gated Partner Discovery link is minted, the walkthrough is scheduled, and the invitation email goes out automatically — with a calendar invite (.ics) attached and a copy to your inbox. When they sign, the meeting time and your Teams link are the first thing they see.
🎥 Meeting setup (Microsoft Teams)
Used by every invitation you send: paste your reusable Teams meeting link once, set the name partners see, and where your copies of the calendar invites go. Every walkthrough you schedule uses this room unless you override it on a specific invite.
Invites
Signed invites are legal records — revoke access instead of deleting. “New link” rotates the URL (old one dies) if a link was lost or over-shared.
Loading…
🏢 Create New Organization
LMI Tool = compliance features only. Loopenta Full = pipeline, borrowers, sequences, and more.
Loopenta
Closing workspace
Every day
Lender partner
More
Loopenta
Your book. Your business.

🏡 Home

Loading…
🎯 Your year, in one number
Two fields, thirty seconds. Loopenta turns it into a monthly pace and keeps score from what you actually do here — nothing is ever fabricated.
✏️ Edit open house
Your QR code and share link never change — already-printed flyers keep working.
Add a contact — 10 seconds, that's it
Edit contact
Changing the note rewrites their next message from it.
🏡 Homeowner advisory
Add what you know — Loopenta flags when to reach out (rate drop, equity, anniversary) using today’s national rate. Estimates only.
🤝 Refer this client
They get a plain-language authorization email first. Nothing is shared until they approve — every step is logged.
Great work! What's your next move?
📅 Schedule Next Contact
Set a follow-up date so this realtor doesn't fall through the cracks
📋 Log a CRA Activity
Log this open house to your CRA Activity Log
💰 Send Buyer Profile to This Realtor
Share a qualified borrower profile while you have momentum
📤 Send Borrower Profile to Realtor
📋 Request Pre-Qualification
Fill in your buyer's details and your MLO partner will reach out to start the pre-qualification process.
📤 Share Flyer with Realtor
Select a realtor to email this flyer link to:
L
Loopenta
Settings Profile
⚙️ Settings
👤 My Profile · Marketing Materials
Profile photo
🔑 Change My Password
🎯 My Alert Preferences
days in same stage
% of deals
%
🎨 Preferences
More customization options coming in future updates.
🔔 Notification Preferences
🏠 Realtor Inactive
🏡 Open House Tomorrow
📅 Follow-up Due
📉 Capture Rate Drop
⚠️ No Activity This Week
📊 Weekly Digest
💳 Account & Billing
🔔 Notifications
You're all caught up! 🎉
🏠 Assign Realtors to Borrower
Marketing Material Preview
Shareable Link:
Generating link...