Compliance and secure development

This page describes the standards and attestations HES FinTech maintains as a vendor, how the platform helps an institution meet its own regulatory obligations, and the secure software development lifecycle behind HES LoanBox releases.

Standards and attestations

Standard What it covers HES FinTech status
ISO 27001 Information security management system Certified (as of 01.07.2025, version 2.1)
SOC 2 Independent attestation of security controls against AICPA criteria Aligned with SOC 2 as of 20.04.2026
GDPR EU data protection Supported through configurable controls and auditable records

Note

ISO 27001 is a certification. SOC 2 is an attestation report against AICPA criteria rather than a certificate, so HES FinTech LLC describes itself as aligned with SOC 2. Compliance of an institution’s lending operations remains the institution’s responsibility — the platform provides controls and auditable records, not automatic legal compliance.

The platform supports the operations a data controller needs — data-subject access, correction, and erasure; data minimization; and records of processing — and is configured to the privacy regime of the institution’s market. Across the regions HES LoanBox serves, that includes:

Regime Region
GDPR European Union
UK Data Protection Act United Kingdom
CCPA California, United States
PIPEDA Canada
Privacy Act Australia
PDPL Saudi Arabia

In every case the institution is the data controller and remains responsible for compliance; HES LoanBox provides configurable controls for these requirements and keeps records that auditors can review. It does not assume the institution’s obligation on its own.

Regulatory alignment

HES LoanBox is configured to the requirements of the institution’s jurisdiction and lending products. The platform provides controls that help automate regulatory workflows and mitigate operational risk, and it keeps auditable records for the examination cycle. It does not make the institution compliant on its own — the compliance of lending decisions and operations remains the institution’s responsibility.

NIST alignment

HES FinTech’s security program is aligned with the NIST Cybersecurity Framework (CSF), which it uses as a reference for identifying, protecting against, detecting, responding to, and recovering from cyber risk. This is a framework alignment, not a certification.

Secure software development lifecycle

Security is built into how HES LoanBox is developed, not added at release. The platform is built on a Java LTS stack, and security practices run across the lifecycle.

Phase Security practice
Design Security requirements and threat consideration for new features
Development Secure coding standards addressing the OWASP Top 10; peer code review
Build Dependency and vulnerability scanning in the pipeline
Test Security testing and, on demand, penetration testing
Release and run Controlled release pipeline incorporating static application security testing (SAST) and software composition analysis (SCA), patch management, and monitoring

Search documentation