Dedicated tenant. Microsoft direct-bill. Built for banks, credit unions, and mortgage lenders that answer to FFIEC, NCUA, FDIC, and OCC examiners. Live in 2 business days or less.
Trusted by 750+ of the Nation's Leading Lenders, Banks & Credit Unions.
TIER 1 MICROSOFT CSP
SOC 2 TYPE II
ZERO TRUST
NIST CSF ALIGNED
FFIEC
GLBA / FTC SAFEGUARDS
NCUA / FDIC
CFPB / GSE AUDIT READY
750+ INSTITUTIONS
SINCE 1999
Since 2004
Calyx Point Hosting
Two decades of lineage
750+
Financial Institutions
Banks, credit unions, mortgage lenders
24/7/365
U.S.-Based Support
Microsoft-certified. Not outsourced.
Tier 1 CSP
Microsoft Direct-Bill
The largest hosting Calyx Point
From $99/mo
Plans Start Here
Azure usage pricing. Not per user.
The Bigger Idea
Your Calyx Server Is the Start of a Bigger Fix
The PointCentral database holds borrower NPI, credit files, income documentation, closing data, and the audit trail of every loan your team has ever touched. Where and how you host it is no longer a back-office decision. It is the highest-impact system in any community bank, credit union, or mortgage lender IT examination.
1
Your database is in regulatory scope.
Under FFIEC, NCUA, FDIC, or OCC review, your PointCentral server lands inside IT General Controls, business continuity, vendor management, and information security. Whatever choice you make about where it lives, your examiner will trace it.
2
Shared tenancy and reseller chains fail today's bar.
Multi-tenant SQL where you cannot answer "who else is on this server" no longer passes the audit bar. Neither does a hosted setup where your provider resells someone else's cloud, because the examiner now traces two vendor relationships instead of one.
3
Private Azure, direct-bill, two hops not three.
ABT runs your PointCentral on a private Microsoft Azure environment dedicated to your institution. As a Tier 1 Microsoft Cloud Solutions Provider buying Azure direct, the chain of custody on your loan data runs workstation to your Microsoft tenant directly to Microsoft. Two hops. Not three.
4
Hosting your Calyx with us is the start, not the end.
From there, your Microsoft 365, Teams, SharePoint, Guardian security, and Copilot can sit in the same Microsoft tenant. One identity. One audit trail. One throat to choke. None of it is required to host Calyx today. All of it becomes an easier yes once your loan database is already with us.
What Makes This Better
Three Controls Your Examiner Will Ask About
Private Tenant, Dedicated Infrastructure
Your PointCentral runs in a dedicated Microsoft tenant for your institution. Dedicated virtual machines. Dedicated SQL instance. Dedicated storage accounts. No shared-tenancy hosting where your borrower data sits in the same database engine as another lender's. When the examiner asks "who else is on this server," the answer is "nobody."
Tier 1 CSP, Tenant in Your Name
ABT is a Tier 1 Microsoft Cloud Solutions Provider (Direct-Bill) with a direct contract to Microsoft. Your Azure tenant is provisioned in your institution's name under your own Microsoft Customer Agreement — you own it; we operate it as your partner of record with delegated admin access you can revoke. Compare a typical AWS-reseller hosting model: the underlying AWS account is owned by the reseller, and your borrower data lives inside their account under their root credentials. When your examiner asks who owns the infrastructure your data sits in, the answer is your institution. Two hops to Microsoft, in your name — not three hops where the middle vendor holds the keys.
Built for Banks, Credit Unions, and Mortgage Lenders
Every control is configured to map to FFIEC, NCUA, FDIC, and OCC expectations out of the gate. Encryption at rest and in transit. Privileged access management. Immutable backup. Change control. Logging and alerting. If your examiner asks for it, we can hand you the artifact that proves it.
Regulatory Readiness
Mapped to Every Examiner Your Institution Answers To
The FFIEC Cybersecurity Assessment Tool was retired August 31, 2025. Examiners now use NIST Cybersecurity Framework 2.0, the CRI Profile v2.1, and CIS Critical Security Controls as the successor references. NIST CSF 2.0 added a sixth core function . Govern . on February 26, 2024.
Your PointCentral hosting environment is in scope for that review. Below: how ABT's private Azure hosting maps to every one of the six NIST CSF 2.0 functions, and to FFIEC, NCUA, FDIC, OCC, CFPB, and PCI examiner expectations.
Documented policies mapped to each NIST CSF 2.0 subcategory. Third-party risk evidence for every component in your PointCentral environment. Governance artifacts in your tenant, ready to hand to an examiner.
Identify
Asset inventory, risk assessment, business environment
Complete asset inventory of the VMs, SQL instance, storage, and network attached to your PointCentral server. Risk assessments on a defined cadence. Annual improvement plan tied to your examination cycle.
Protect
Identity, access, data, platform security, training
Entra ID conditional access on every admin path. Encryption at rest and in transit, FIPS 140-3 hardware-backed keys on request. DMARC enforcement, Defender hardening, Tokenator zero-tolerance session revocation.
Detect
Continuous monitoring, anomaly detection
Microsoft Sentinel correlation across PointCentral, identity, endpoint, and email telemetry in one pane. Guardian Managed Extended Detection and Response watching your tenant 24/7/365 from the United States.
Respond
Incident response planning, analysis, mitigation
Documented incident response runbook tailored to your institution. Forensic log retention so investigators have what they need on day one. Guardian MxDR analysts on-call to triage, contain, and work an incident alongside your team.
Recover
Recovery planning, restoration, communication
Nightly backup with geo-redundant copies in a second Microsoft region. 16-nines storage durability on the geo-redundant backup tier. Microsoft's published storage SLA. Documented RTO and RPO tied to your BCP plan.
Reference: nist.gov/cyberframework (CSF 2.0, released February 26, 2024). FFIEC CAT retired August 31, 2025 per OCC Bulletin 2024-25 and the FFIEC joint statement.
Under the Hood
The Architecture Behind the Hosting
Every control your IT team and examiner will trace is documented and auditable. Full architecture diagrams and control mappings are available under NDA.
Availability and Resilience
PointCentral runs on your own dedicated server with Microsoft Azure redundancy built in at every storage layer.
3 copies of your data maintained automatically inside the data center
11 nines (99.999999999%) durability on live storage, Microsoft's published SLA
Nightly backup with copies in two Microsoft regions for disaster recovery
16 nines durability on the geo-redundant backup tier
Documented RTO and RPO tied to your BCP plan
Encryption and Key Management
Every byte of borrower data encrypted in transit and at rest. Keys in Azure Key Vault Premium, segregated per institution.
TLS 1.3 client-to-server
AES-256 at rest on SQL and storage
Customer-managed keys available
FIPS 140-3 Level 3 hardware-backed keys on request (Azure Managed HSM)
Transparent Data Encryption on full Calyx DB
Network Architecture
Encrypted traffic over Microsoft Azure's network, with private-circuit upgrades available for institutions that need them.
TLS 1.3 encryption end-to-end on every connection
Azure VPN gateway available for institutions that require it
ExpressRoute private circuit available on request (99.95% SLA)
NSGs enforcing least-privilege network access
Defender for Cloud continuous posture monitoring
Identity and Access
Access gated through Entra ID conditional access with hardware-backed MFA on every admin path.
Privileged Access Workstations for ABT admins
Just-in-time privileged role activation
Tokenator zero-tolerance session revocation
Role-based access with quarterly review
Session logging retained for forensic review
Private vs Shared
What Private Hosting Actually Means
"Hosted in the cloud" is not a differentiator. Every Calyx hosting provider uses someone's data center. The real question for a CISO is what sits between your borrower data and the next tenant on the same infrastructure. Below, the comparison split into two views: architecture & tenancy, and operations & compliance.
Architecture & Tenancy
Where your data lives and who shares the database engine.
Control
ABT Private Azure
Typical Shared Hosting
Cloud platform
✓Microsoft Azure, Tier 1 CSP direct-bill. Tenant provisioned in your institution's name under your own Microsoft Customer Agreement.
−Typically a third-party cloud (often AWS) provisioned in the reseller's account, not yours. You access it; they own the root.
Database tenancy
✓Dedicated SQL instance per institution. No co-mingled databases, no shared connection pool.
−Shared SQL server with tenant-per-database, or shared tables keyed by tenant ID.
−Shared VM farm, shared storage pool, shared subnet. Tenant isolation is software only.
Account ownership
✓Your institution holds the Azure tenant and the MCA. ABT operates with delegated admin access you can revoke.
−Reseller holds the AWS account and root credentials. Customer access is scoped IAM under their account.
Vendor chain
✓Two-link chain: your institution → ABT → Microsoft. One audit trail.
−Three-link chain common: institution → host → reseller → underlying cloud. Two audit trails to trace.
Operations & Compliance
Patching, backup, encryption, network, and incident posture.
Control
ABT Private Azure
Typical Shared Hosting
Patch scheduling
✓Coordinated with your institution's change window. Advance notice, pre-tested builds.
−Vendor-driven windows that apply to all tenants at once. Limited coordination.
Backup and retention
✓Nightly backup with geo-redundant copies in a second Microsoft region. Backup retention configurable to BSA, NCUA, and SAR record-keeping requirements.
−Typically nightly full backup with limited retention. Extending beyond vendor default is often an add-on.
Encryption and keys
✓TLS 1.3, AES-256 at rest, Azure Key Vault Premium. FIPS 140-3 Level 3 hardware-backed keys available on request.
−Shared encryption keys common. FIPS 140-3 validated hardware rarely offered.
Network path
✓TLS 1.3 encrypted traffic over Microsoft Azure's network. ExpressRoute private circuit available on request for institutions that require it.
−Public-internet VPN, typical. Private circuit rarely available at single-institution size.
Incident scope
✓A security incident in your tenant stays in your tenant. Forensic boundary is your institution.
−A platform-level incident can pull every tenant into the same investigation.
Pricing model
✓Azure usage pricing. We charge by Azure usage, not user count. New installations start at $99 a month. Migrating data? We size the plan to your Azure usage. All Azure usage is included. Same rate year over year. A fraction of what you'd pay on a per-user system.
−Per-user pricing typical, with cloud consumption fees often billed back as pass-through. Year-one promotional pricing followed by tier increases.
From the ABT YouTube Channel
What most MSPs won't tell you about hosting your Calyx environment.
Most MSPs reselling cloud hosting don't run the data center, don't write the SQL retention policy, and don't sign the BAA the FFIEC examiner is going to read. We do all three. Watch the 49-second version, then read the side-by-side comparison above.
Once your PointCentral lives in your dedicated Microsoft tenant, every other Microsoft service your bank, credit union, or mortgage business needs can sit in the same tenant, on the same identity, with the same audit trail.
Standard
Microsoft 365 in the Same Tenant
Email, Teams, SharePoint, OneDrive, and endpoint security live in the same Microsoft tenant as your PointCentral database. One identity. One DLP policy set. One audit trail. No cross-tenant data exchange surface to secure.
Available
Azure Virtual Desktop
Windows 11 virtual workstations for remote loan officers, contract processors, and hybrid employees. Available as an integrated option on your tenant. Keeps PointCentral access inside the ABT security boundary even on personal devices.
Standard
Guardian Security Operating Model
Every PointCentral tenant runs under the Guardian operating model: Entra ID hardened, Defender tuned, DMARC enforced, Tokenator zero-tolerance session revocation, Sentinel correlation across the stack. Guardian MxDR watches 24/7/365 from the United States.
Available
Microsoft 365 Copilot, Ready When You Are
With Microsoft 365 and PointCentral data already in one governed Microsoft tenant, Copilot readiness is a configuration step, not a migration project. When you are ready to evaluate generative AI for loan origination, underwriter research, or compliance drafting, the governance foundation is already under you.
Standard
DocumentGuardian for Borrower Documents
Send sensitive borrower documents encrypted, audited, with retention controls. DocumentGuardian is included in your hosting fee. No separate vendor, no separate bill, no separate audit trail.
The Consolidation Journey
Once Hosting Is Solved, Here Is What Comes Next
Hosting your Calyx with ABT is step one. The reason it matters is what it unlocks downstream. With your loan origination database, your Microsoft 365 footprint, and your security operating model already in one governed Microsoft tenant, the two questions every FI board is now asking get faster, cheaper answers.
Next Step: Security Posture
NIST CSF 2.0 Assessment for Financial Institutions
FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025. NIST CSF 2.0 is the framework examiners are now mapping community banks, credit unions, and mortgage lenders against. Our 6-to-8-week assessment grades your institution across all six functions, including the new Govern function added in 2024.
Maps your environment to Govern, Identify, Protect, Detect, Respond, Recover
Identifies gaps before your next OCC, FDIC, or NCUA exam
Microsoft-native scoring across Entra ID, Defender, Purview, and Sentinel
Microsoft 365 Copilot Readiness for Financial Institutions
Once your PointCentral and your Microsoft 365 are in the same Microsoft tenant under the same Guardian operating model, the heavy lifting for Copilot is already done. The remaining work is governance configuration, not migration. Our Copilot Readiness assessment confirms your data labels, permissions, and Purview policies are tight before you turn Copilot on.
Sensitivity label coverage check across SharePoint, OneDrive, Teams, Exchange
Oversharing detection on the documents Copilot will index
Conditional access and DLP policy review tuned for Copilot prompt traffic
Tell us what you run today. We will map your current Calyx environment, your Microsoft 365 footprint, and your security posture against what a dedicated Microsoft tenant under Guardian would look like, and show you the consolidation path on a single call.
New PointCentral installations start at $99 a month. We bill by Azure usage, not user count. Bringing data with you? We size the plan to match. Either way, it's a fraction of per-user pricing.
Calyx Software hosting partner since 2004 · Tier 1 Microsoft Cloud Solutions Provider · Microsoft-certified engineers, United States
How It Works
Live on a Private Azure Tenant in 2 Business Days or Less
From scope call to your loan officers logging in to a dedicated Microsoft tenant: 2 business days or less. Your existing Calyx environment stays up the whole time. Cutover happens on the maintenance window your IT team picks.
1
Step 1 · Scope Call
One Call, Written Migration Plan
Our Azure specialist reviews your environment, confirms regulatory scope, and gives you a written migration plan. No pressure. You keep the plan whether you move forward or not.
Current-state inventory and gap assessment
Tenant design, network, and storage architecture
Cutover window picked by your IT team
2
Step 2 · Migration
Cutover in 2 Business Days or Less
We provision your private Azure subscription, migrate the PointCentral database, and stage the cutover during a maintenance window of your choosing. Full cutover in 2 business days or less.
PointCentral Live. The Rest Comes When You Are Ready.
PointCentral runs on dedicated Azure infrastructure. Your loan officers reach real United States Microsoft-certified people 24/7/365. The rest of your Microsoft footprint can follow when you are ready.
PointCentral live on dedicated Azure
24/7/365 Microsoft-certified U.S. support
Door open for M365, Guardian, volume discounts
Frequently Asked Questions
What CISOs and IT Directors Ask Us First
Eleven answers your IT team and your examiner will want before signing a hosting contract. Each one mirrors the structured data this page publishes for answer engines.
How long does a migration to PointCentral on private Azure take?+
2 business days or less. The scope call defines the cutover window your IT team picks. Your existing Calyx environment stays up the whole time. We provision your private Azure subscription, migrate the PointCentral database, and stage the cutover during the maintenance window of your choosing. Your loan officers log in to PointCentral on the new tenant the next morning.
Do I have to move my Microsoft 365 to ABT to host PointCentral here?+
No. Calyx hosting is a standalone decision. Many of our customers host PointCentral with us for years before they consolidate Microsoft 365. The door is open for that conversation when you are ready, on your timeline. Once Calyx is already with us, every other Microsoft consolidation step (Microsoft 365 takeover, Guardian standard rollout, Copilot readiness, volume discounts, one bill) becomes a much easier yes.
What happens during a regional Azure outage?+
Your nightly backup is geo-redundant, replicated to a separate Microsoft region with 16 nines durability. ABT restores from the geo-redundant backup tier per your documented BCP plan. Zone-redundant and multi-region active failover are available as upgrade options for institutions that require continuous availability across regional outages.
What encryption standards does ABT use for PointCentral hosting?+
AES-256 at rest under SQL Transparent Data Encryption. TLS 1.3 in transit. Customer-controlled keys in Azure Key Vault Premium. FIPS 140-3 Level 3 validated hardware-backed keys available on request via Azure Managed HSM. The Calyx database, the file shares, and the backups all use the same envelope.
Is ABT's PointCentral hosting FFIEC examination ready?+
Yes. Mapped to NIST CSF 2.0 six functions (Govern, Identify, Protect, Detect, Respond, Recover) and aligned with the FDIC 2026 five-domain integrated examination model. The FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025; NIST CSF 2.0 is the framework examiners are now mapping community banks, credit unions, and mortgage lenders against. Environment-specific SOC 2 Type 2 attestation is provided to FI customers under NDA as part of our standard due diligence package.
How is ABT's hosting architecture different from other Calyx hosting providers?+
Three architectural differences. First, ABT runs every PointCentral institution on private Microsoft Azure with the Microsoft Customer Agreement in your institution's name. Most other Calyx hosting in the market today is built on AWS through a SaaS-on-cloud-reseller chain, where the cloud account holding your borrower data belongs to the middle vendor, not to you. Second, ABT has been a Calyx hosting partner since 2004, earlier than any other current Calyx hosting provider. Third, ABT is a Tier 1 Microsoft Cloud Solution Provider that buys Azure directly from Microsoft, with no reseller layer in the chain. The full side-by-side comparison, including support hours, storage policy, and durability guarantees, is documented in the section above this FAQ.
Who controls the encryption keys?+
The financial institution. ABT operates the platform. We do not hold or read your keys. Customer-controlled keys live in Azure Key Vault Premium, and FIPS 140-3 Level 3 hardware-backed keys are available in Azure Managed HSM on request. Key rotation, key revocation, and audit-log access stay inside your tenant, your identity boundary, and your compliance officer's reach.
How quickly does ABT patch critical vulnerabilities?+
Managed tenants receive Microsoft Patch Tuesday updates within the Guardian advisory cadence. Critical vulnerabilities on the CISA Known Exploited Vulnerabilities list are patched inside the CISA-published deadline, not after it. As a recent example, April 2026 Patch Tuesday covered 167 CVEs including two actively exploited zero-days; managed tenants were patched inside the CISA KEV deadline. The Guardian advisory feed publishes our patch posture and exception list on the same cadence Microsoft publishes the bulletins.
What regulatory records retention does the platform support?+
Bank Secrecy Act records 5 years (31 CFR 1010.430). NCUA vital records permanent under 12 CFR Part 749 Appendix A. Suspicious Activity Report records 5 years from filing date. Backup retention up to 10 years with customer-controlled Transparent Data Encryption. Geo-redundant storage and immutable backup vaults are available for institutions whose retention policy requires write-once-read-many guarantees.
Does ABT host other Microsoft workloads for financial institutions?+
Yes. ABT is the largest Tier 1 Microsoft CSP hosting Calyx Point and other Azure services: Microsoft 365, MortgageExchange, Guardian MxDR, Azure Virtual Desktop, and Microsoft 365 Copilot all in a single Azure tenancy. 750+ financial institutions run their Calyx and Microsoft services with us, across community banks, credit unions, and mortgage lenders. Hosting your Calyx with us is the starting point. The rest of your Microsoft footprint can follow on your timeline.
How should I evaluate ABT versus other Calyx PointCentral hosting providers?+
Ask every provider four questions before you sign a contract. Where does my borrower data physically live (private Microsoft Azure, AWS, or a colocation facility)? Is my SQL instance dedicated or shared with other lenders on the same database engine? What is the actual support staffing model (United States, Microsoft-certified, 24/7/365, or business hours through a help desk)? How is the relationship structured (Tier 1 Microsoft CSP direct-bill, or a reseller chain with two audit trails)? Our written buyer guide for community banks, credit unions, and mortgage lenders walks through each of those questions, the documentation an examiner will ask for, and how to put the answers on paper before you commit. Read the CISO buyer guide.
How much does PointCentral hosting cost?+
We don't charge by user. We charge by your Azure usage. New PointCentral installations start at $99 a month. That's the price for a clean install with no historical data to migrate. If you're moving from another host and want to bring your old data with you, tell us how much data you have and we'll give you an estimate. More Azure usage means a bigger plan. Less Azure usage means a smaller plan. You stay in control. If you trim old loans or archive unused files, your Azure usage drops and your plan goes down with it. We include all your Azure usage in one monthly fee. No separate Azure bill. No surprise extra charges. The rate you pay in year one is the same rate you pay in year five. Even with heavy Azure usage, our pricing is a fraction of what you'd pay on a per-user system.
Talk to an Expert
Talk to a Calyx Specialist
Get a scoped migration plan and a live demo of the Guardian baseline. No pressure. No long sales cycle. The plan is yours to keep, whether you move forward with us or not.
SOC 2 Type II
Tier-1 CSP Direct-Bill
NIST CSF 2.0 Aligned
2004
Calyx Hosting Partner Since
750+
Financial Institutions
2 Days
Or Less Cutover SLA
Get Your Scoped Migration Plan
A written plan you keep, whether you move forward or not.
I am interested in... (optional)
PointCentral migration plan
FFIEC + NIST CSF 2.0 readiness
Microsoft 365 + Guardian consolidation
Scoped pricing for my institution
First name is required
Last name is required
Valid email is required
Response within 1 business day. No obligation.
You are in.
A Calyx Specialist will review your request and reach out within one business day.