Least privilege and multi-factor authentication
Staff get only the access their job needs, and sign-in requires multi-factor authentication.
The security principles behind TS LMS and TS HRM + EWA.
Staff get only the access their job needs, and sign-in requires multi-factor authentication.
Data is encrypted in transit with TLS 1.3 and at rest with AES-256; sensitive customer fields are encrypted field by field.
We record who did what and when, in a way that shows if a record is altered afterwards. Money movements need two people.
Code review, automated vulnerability scanning and separate development, test and production environments are part of every release.
We assess the system for vulnerabilities regularly and fix what we find by priority.
Data is backed up in encrypted form, and a recovery plan covers disasters and outages.
Development and operations contractors sign confidentiality agreements, and their access is limited to what they need.
The platform runs on Google Cloud. Each lender runs in its own environment; data is not shared with other lenders.
Designed with reference to Japan’s FISC security guidelines for financial institutions.
Detailed architecture and operating controls are shared individually with clients in an active engagement, under NDA. Request a demo