On-premise reporting for title agencies.
You shouldn't have to hand over your data to see your data. On-premise reporting runs inside your own network and queries your production database in place — so there is no copy of your clients' files in a vendor's cloud, no data-processing agreement, and nothing new on your outbound firewall except a license check.
What "on-premise" actually has to mean
The term gets used loosely. A hosted agent that ships your rows to a vendor's cloud for rendering is not on-premise, and neither is a connector that syncs a nightly copy. Three tests separate the two.
On a server you own, against the production database directly — not against a replica somewhere else. If the vendor needs a copy to query, the data has left.
In your own memory, on your own server, served over your own site. A chart assembled in a vendor's cloud means the underlying rows went there to assemble it.
Ask for the complete list of outbound calls, not a summary of it. "Minimal" and "anonymized" are answers that avoid the question.
How EscrowIQ answers those three
EscrowIQ connects to your SoftPro Select database with a SQL account that only ever needs db_datareader. Every query is a SELECT; no code path writes, updates, or deletes. Grant read-only access and the application works exactly as intended — that is the test.
Every report page, chart, and export is generated on the Windows server you installed it on and served over your own IIS site to users your Active Directory authenticates. Nothing is pre-computed or cached in a system Hubmission operates.
A license check-in a few times a day — license key, install ID, app version, nothing else — and, only if your admin turns it on and configures it, the scheduled report emails they set up. No analytics SDK, no telemetry, no crash reporting, no background sync.
Why this matters more for title than for most industries
The data is the sensitive kind
Title and escrow files carry names, addresses, loan details, and wire instructions for the parties to a real estate transaction. Every additional copy is an additional place that has to be defended.
Someone will ask you about it
Underwriters and lender clients ask what third parties touch your production data. "None — the reporting runs inside our network" is a shorter answer than a vendor questionnaire and a data-processing agreement.
You can verify it yourself
Set the SQL login to db_datareader only and confirm the application still works. Watch the server's outbound connections and confirm you see the license check-in and nothing else. Both take an afternoon.
It survives the security review
We provide a security architecture document and a completed vendor security questionnaire on request, under NDA if your process requires it. Request the documentation.
Questions
How can a title agency get dashboards without moving client data to the cloud?
Install the reporting application on a server inside your own network and point it at your production database. EscrowIQ does exactly this: it publishes to an IIS site on a Windows server you control, reads your SoftPro Select database with a read-only SQL account, and renders every report on that same server. No report data and no SoftPro data is transmitted off your network.
Does any data leave my network?
Two things, and this is the complete list. First, a license check-in runs a few times a day and sends your license key, a stable install identifier, and the app version — no SoftPro data, no report data, no customer or staff information. Second, if an admin turns on the optional Report Subscriptions add-on and configures it, the specific report they chose is emailed on the schedule they set to the recipients they listed. Nothing else is transmitted.
What happens if the license server is unreachable?
The application keeps working on its last known-good license status for 14 days before anything changes. It fails open toward continuing to run, not toward contacting us more often.
What SQL permissions does the reporting tool need?
Only db_datareader on your SelectDb. If EscrowIQ needed write access anywhere it would fail at setup — granting read-only access is the simplest way to verify the claim.
Can I restrict who sees which reports?
Yes. Sections and individual report pages map to your Active Directory security groups, so executive revenue views stay with leadership and tasking queues stay with operations. There is no separate login system — access rides entirely on your existing AD.
Do you have security documentation for a vendor review?
Yes — a detailed security architecture document and a completed vendor security questionnaire, written for a procurement or security review rather than as a marketing summary. Request them at /security-request.
Your data never leaves your network.
Installs in minutes on the server you already run SoftPro on. See it for yourself in thirty minutes.