411 Capital is starting from zero. Everything is currently manual. This board maps every phase of the build: what is done, what is missing, what gets automated, and what stays human.
Full loan lifecycle from borrower contact to post-close. Color shows what is automated (teal border), manual (orange border), missing/not built (red dashed), or partial (gold border).
Every task mapped to its layer. Some will always need a human. Others should never need one. Goal: push every repetitive decision to automation and protect human time for real judgment calls.
Three distinct layers power the system. The Brain is the encoded decision logic extracted from the principals. The Automations are the workers that execute without human involvement. The Human Actions are the steps that always require a real person — judgment calls, legal sign-offs, and relationship moments the system cannot replace.
Decision logic that must be extracted from the principals and encoded into the system before any automation can work. This is the rulebook everything else runs on.
These workers run 24/7 without human involvement. They read the Brain's rules and execute. Once built, no one touches them unless the rules change.
These steps require a real person every single time. Judgment calls, legal sign-offs, relationship moments, and financial authorizations the system cannot and should not replace.
Every data category needed to run the system. For each one: recommended partner, alternatives, and the questions to confirm in the workshop.
| Provider | Best For | Pros | Cons | Cost |
|---|---|---|---|---|
| HouseCanary ⭐ Recommended | Hard money lenders, fix-flip ARV | AI-powered AVM, ARV scoring built-in, rental forecasts, lender-grade accuracy | Premium pricing. Overkill for very small portfolios. | ~$0.50–$2 per report |
| ATTOM Data ⭐ Recommended | Comprehensive: tax, deed, ownership | 158M+ properties, tax history, deed, foreclosure data, neighborhood analytics | AVM less refined for fix-flip vs HouseCanary | From ~$199/mo |
| CoreLogic | Enterprise mortgage lenders | Industry gold standard. 99.9% coverage. 50 years of data. | Enterprise pricing only. Not startup-friendly. | $1,000s/mo min |
| Zillow API ⚠️ | Consumer apps | Free/low cost. Familiar to borrowers. | Restricted commercial use per TOS. Not for lending decisions. | Free with restrictions |
| Estated API | Startups, MVP stage | Dev-friendly REST API, affordable, free trial | Less depth than ATTOM or CoreLogic | Pay-per-call |
| Provider | Best For | Pros | Cons | Cost |
|---|---|---|---|---|
| Middesk ⭐ Recommended — Entities | Business entity verification (LLC, corp) | Direct pipelines to all 50 Secretaries of State plus IRS. Beneficial ownership. 300+ lender clients. | Business only — not personal KYC. Pair with Persona. | Per-verification |
| Persona ⭐ Recommended — Individuals | Individual borrower KYC | Full KYC: government ID scan, selfie liveness, OFAC/AML watchlist. Borrower-friendly UX. | Primarily personal KYC. Pair with Middesk for entities. | Usage-based, free dev |
| DataVerify | Mortgage-specific fraud detection | NMLS verification, occupancy fraud, undisclosed debt detection | Over-engineered for private lending MVP stage | Subscription + per-report |
| Socure | High-volume digital identity | Industry-leading fraud detection accuracy. Real-time AI scoring. | Enterprise pricing. Better for high-volume fintechs. | Enterprise contract |
| Provider | Best For | Pros | Cons | Notes |
|---|---|---|---|---|
| CoreLogic Credco ⭐ Recommended | Mortgage-grade tri-merge credit report | Pulls from all 3 bureaus in one report. Industry standard for mortgage lenders. | Requires NMLS licensing or lender credentialing. | Confirm if 411 Capital already has access via attorney relationships. |
| Plaid | Bank account / income verification | Borrower connects bank, 2 years of transactions plus income verification. Used by Freddie Mac AIM. | Not a credit score product. Supplementary only. | Good for validating stated employment income. |
| Provider | Status | Automation Opportunity | Priority |
|---|---|---|---|
| Qualia + Titlewave ⭐ | Fully operational but data re-entered manually | Build intake-to-Qualia API push to eliminate re-entry. Biggest closing-side time save. | High Priority |
| Camson Crown / Skyline | Already used via Qualia Marketplace | Auto-trigger lien search order on deal approval — currently initiated manually | Medium |
| Simplifile | Already used for post-close recording | Auto-trigger recording package creation on closing completion | Medium |
| Tool | Role | Pros | Cons | When to Use |
|---|---|---|---|---|
| Airtable ⭐ Start Here | Scoring engine + deal database | Formula fields for scoring, Zapier integration, visual views, no-code friendly, affordable | Not a full CRM. Migrate to HubSpot as volume grows. | Build and test scoring logic first. MVP stage. |
| HubSpot | CRM with pipeline + email + automations | Free tier generous. Email templates, deal tracking, notifications, reporting. Scales well. | Can get complex. Better once volume is established. | Borrower communications and deal stage tracking. |
| Zapier / Make.com ⭐ Required | Automation glue between all tools | Connects intake, Airtable, HubSpot, Dropbox, DocuSign, Qualia without code | Complex zaps can be fragile. Make.com steeper learning curve. | Zapier for simple flows. Make.com for complex branching. |
11 critical gaps identified. Red cards must be collected before the workshop or in the workshop itself — the system cannot be built without them. Yellow cards can come after.
No document shows how interest rate or origination points are calculated. System cannot auto-generate a term sheet without this.
4 products exist but no documented decision tree for which deal goes into which program.
No documented list of automatic no's. Without this the scoring engine cannot generate a reliable Red-tier decision.
Referenced in AI notes but not shared. Must be in structured format (CSV or database) for API cross-reference to function.
Draft weights proposed but never validated by the client. Need their sign-off before scoring can be trusted.
Application collects ARV but no documented method exists for how 411 Capital validates or challenges a borrower's stated number.
Real Estate Owned section used as experience proxy but no scoring rubric exists for 0, 1-3, 4-10, or 10+ completed deals.
Notes reference background check companies but no specific vendor is named. Must choose KYC and KYB partners before build begins.
Zillow is obvious but restricted for commercial use. Must select an AVM partner before the property worker can be built.
Renovation deals require a Scope of Work but no standard for what makes an SOW credible is documented anywhere.
Once a loan is funded there is no documented monitoring process. Draw schedules, inspections, and payment escalation are all undefined.
7 blocks across 110 minutes. One workshop to extract everything needed to build the system. Expand each block to see all questions.
A full assessment of how complex this build is, what can go wrong, what the law requires, and what must be protected. Ground zero start. Every risk is rated by severity.
The entire system depends on getting 411 Capital's decision logic out of the principals' heads and into structured rules. If the workshop is rushed, skipped, or answers are vague, the scoring engine will be built on guesswork. A model built on wrong weights will produce wrong scores — and the lender will lose trust in the system before it is even tested.
Hard money lending looks simple on the surface but expands fast once you get into it. Rehab draw schedules, construction inspection protocols, default waterfall processes, extension negotiations — each one is a full sub-system. Without a hard boundary, this project can grow 3x beyond the MVP without delivering a working product first.
The most common failure in automation projects is not technical — it is that the humans who were supposed to use the tool go back to their old habits. If the system adds steps without immediately reducing time, the team will bypass it. If the scoring output conflicts with gut feel on early deals, trust collapses quickly.
The scoring weights are theoretical until tested against real past decisions. If 411 Capital cannot share historical deal data (even anonymized) — approved, declined, and defaulted loans — there is no baseline to validate the model against. The weights will be educated guesses until enough live deals accumulate.
Third-party APIs — Middesk, ATTOM, HouseCanary, Qualia — update their endpoints, change response schemas, or deprecate fields. A Zapier automation built today can silently fail if a field name changes upstream. The system can appear to be working while scoring on stale or empty data.
If the Do Not Lend List is used to systematically block certain borrowers and there is no structured process for adding, removing, or auditing entries, it becomes a discrimination risk. A borrower could argue they were blocked based on protected characteristics if entries are not consistently documented with legitimate business reasons.
The Equal Credit Opportunity Act requires any creditor — including private and hard money lenders lending to businesses — to provide a written statement of specific reasons when taking adverse action on a credit application. The CFPB confirmed in 2022 that this applies to automated scoring models too. If the system declines a deal and cannot explain exactly why in plain language, the lender is in violation. "Black box" scores are explicitly non-compliant under ECOA and Regulation B.
If 411 Capital pulls a credit report as part of underwriting, the Fair Credit Reporting Act governs how that information is used, stored, and communicated. Borrowers are entitled to know if an adverse action was taken based on credit report data and must receive a notice pointing them to the reporting agency. Credit data cannot be stored indefinitely or used for purposes beyond the original loan decision.
The Gramm-Leach-Bliley Act applies to all financial institutions including private lenders. It requires a written information security plan, employee training, vendor oversight, and annual risk assessments. Under the 2023 updated Safeguards Rule, lenders must encrypt customer data both in transit and at rest, implement multi-factor authentication, and appoint a qualified individual to oversee the security program. A single breach without a documented safeguards plan means the lender is personally liable.
Hard money lending license requirements vary significantly by state. Business-purpose loans secured by commercial property or 5+ unit residential are generally exempt from NMLS requirements. However, business-purpose loans on 1–4 unit residential property are a gray area — California, Nevada, Oregon and 15+ other states have tightened requirements since 2025. The key distinction: consumer purpose = always licensed; business purpose on 1–4 family = state-dependent.
Any automated scoring model in lending carries the risk of disparate impact — producing outcomes that disproportionately harm a protected class even without discriminatory intent. If the model uses neighborhood or zip code data, property location scoring, or any variable that correlates strongly with race, ethnicity, or national origin, the lender is exposed to Fair Housing Act and ECOA challenges. This is not theoretical — regulators are actively investigating algorithmic lending bias.
The Bank Secrecy Act requires financial institutions including private lenders to have anti-money-laundering programs, conduct customer due diligence, and file Suspicious Activity Reports for transactions that appear unusual. With automated KYC and KYB tools doing identity checks, the system must log every verification and flag anomalies for human review. Automated OFAC watchlist screening is mandatory.
Borrower application data — SSNs, bank statements, entity documents, credit reports — cannot be held indefinitely. GLBA, FCRA, and state privacy laws (California CCPA, Virginia VCDPA) each have specific retention windows and deletion rights. An automated system that never purges data creates a compounding liability as the database grows.
The system handles Category 1 sensitive financial data — the most regulated and highest-value target for breaches. Every layer must be designed with security as a first principle, not bolted on after.
The intake form collects full legal name, SSN or EIN, date of birth, address, financial statements, and bank information. This is the highest-risk data collection point. If the form is built on a platform that does not have SOC 2 Type II certification, the lender accepts full liability for any breach of that data during transmission or storage.
Every API partner — Middesk, ATTOM, HouseCanary, Qualia, DocuSign, Zapier — has access to some portion of borrower data. GLBA requires the lender to conduct vendor due diligence and have written contracts with each vendor confirming their security standards. If a vendor is breached and the lender cannot demonstrate they vetted and monitored that vendor, the lender shares legal liability.
Hard money lending involves large wire disbursements at closing. Automated systems that send approval notifications and term sheets create new social engineering attack surfaces — a fraudster who intercepts a notification email can attempt to redirect wires by impersonating the lender or borrower. Wire fraud in real estate is one of the fastest-growing categories of financial crime.
If HubSpot or Airtable holds full borrower files including SSNs, credit data, and bank statements, those platforms become regulated data stores. A misconfigured sharing permission, an accidentally public Airtable base, or an exported spreadsheet sent to the wrong email address creates a reportable breach. Many CRM-related breaches happen through exactly these mundane mistakes, not sophisticated attacks.
In lending, an audit trail is not optional — it is how the lender defends every decision in a regulatory examination or legal dispute. The system must record who reviewed a deal, when, what version of the score they saw, what changed, and who approved the final term sheet. If the audit trail is incomplete, the lender cannot reconstruct a decision — which is a regulatory violation under GLBA and ECOA record-keeping requirements.
As the team grows — additional underwriters, a closing coordinator, a loan officer — access permissions compound. A former employee with retained access to a Zapier account, an Airtable base, or a Dropbox folder is a significant uncontrolled risk. Most small financial services firms never formalize offboarding checklists, meaning ex-employees often retain system access indefinitely.
The biggest technical challenge is that the scoring model is not a one-time build — it is a system that must be updated as market conditions change, as new deal patterns emerge, and as the lender gains confidence in specific risk categories. A scoring model built in Airtable formulas will be brittle and hard to update. A model built in a no-code automation tool like Make.com will be slow. The right architecture separates the weights from the logic so that updating weights does not require rebuilding workflows.
The property data worker pulls from ATTOM or HouseCanary, the borrower check worker pulls from Middesk and Persona, and the credit worker may pull from a separate bureau. Each API returns data in a different format, with different field names, different confidence scores, and different rates of null values for rural or uncommon properties. A scoring engine that receives a null from one API and treats it as zero will score a deal incorrectly.
Qualia is used for closing management and already handles title ordering. The plan is to push intake data to Qualia automatically on deal approval to eliminate re-entry. However, Qualia's API access and webhook capabilities vary by account tier and are not publicly documented in full. Depending on the account, the integration may require Qualia professional services or may only support limited data push via their Marketplace tools.
No-code automation tools like Zapier and Make.com are excellent for MVP builds but have known failure modes at scale: rate limiting, execution timeouts on long-running workflows, poor error visibility when a step silently fails, and data loss if a zap errors mid-run with partial writes. A workflow that sends a borrower through five steps and fails on step three may leave incomplete data in the CRM with no alert.
Auto-generating term sheets and adverse action notices as PDFs requires a templating layer that reliably populates variable fields without formatting errors. Merged fields that overflow cells, dollar amounts that lose formatting, or dates that render incorrectly can create term sheets that look unprofessional or — worse — contain legally ambiguous amounts. DocuSign's templating and tools like Documint or Anvil handle this but require careful template design.
An Airtable + Zapier + HubSpot stack is an excellent MVP. At high volume — say 500 applications per month — Airtable row limits, Zapier task caps, and HubSpot plan tiers become constraining. This is not a current problem but it is a planned obsolescence that should be acknowledged from day one so the architecture is designed to be migrated to without rebuilding from scratch.
The most dangerous failure mode is a false positive — the system scores a deal green, the lender approves it without human review, and the deal defaults. On a $500,000 hard money loan, one uncaught bad deal can erase months of revenue. The risk is highest in the early months when the model has no performance history to validate against.
A weighted average score can hide a catastrophic weakness. If a borrower has perfect experience (40/40 on that category) but zero exit strategy viability (0/20 on that category), the aggregate score might still reach 75 — which looks like a conditional approval. But a deal with no viable exit is a loss regardless of how experienced the borrower is. Aggregate scores can obscure category-level red flags.
A scoring model calibrated in a rising market may systematically over-approve deals in a flat or declining market. Exit strategy weights built on 2021–2023 fix-flip data may be too optimistic for 2025 conditions. A model that is never re-trained will become progressively less accurate as market conditions shift.
The experience category systematically penalizes first-time borrowers. This is intentional — experience reduces risk — but if the weights are too heavy on experience, the system will decline all new-to-market borrowers regardless of deal quality. This could mean missing genuinely good deals from capable first-timers with strong properties and exit plans.
These are not optional. Every item below must be in place before the system handles a real borrower application.