Overview
HES LoanBox is delivered as configurable lending infrastructure that a financial institution runs either in the cloud, managed by HES FinTech, inside its own environment on-premises, or in a hybrid mode. Security is therefore a shared concern rather than a single product feature. The applicable security controls and the division of responsibilities between HES FinTech and the customer depend on the selected deployment model, system configuration, and connected services.
This section explains the platform’s security architecture, how responsibility is divided between HES FinTech and the institution, and how that division shifts with the deployment model.
Security architecture at a glance
HES LoanBox applies controls at distinct layers. Each layer is documented on its own page in this section.
| Layer | What it covers |
|---|---|
| Identity | Authentication, roles, permissions, password and lockout policy (delegated to Keycloak) |
| Application and API | Encryption, OWASP-category defenses, API authentication, KYC/KYB, anti-fraud |
| Infrastructure | Cloud and on-premises hosting, environments, backups, availability, disaster recovery |
| Governance | Activity logging, traceability, monitoring, incident response |
| Standards | ISO 27001, SOC 2, privacy regulation, NIST alignment, secure development lifecycle |
The platform is API-first: every capability is reached through authenticated, role-authorized APIs, and the same access rules apply whether a request comes from the user interface, an agent portal, a borrower portal, or an integration.
Shared responsibility model
Security divides into two parts: the security of the platform, which HES FinTech maintains, and the security of the deployment around it, which is shared with the institution and the cloud provider, in cloud deployments. The table shows where each responsibility sits.
| Area | Cloud (HES-managed) | On-premises (institution-managed) |
|---|---|---|
| Physical and data-center security | Cloud provider | Institution |
| Operating system and patching | HES FinTech | Institution |
| Platform code and updates | HES FinTech | HES FinTech (release), institution (apply) |
| Identity configuration (Keycloak realms, roles, policies) | Institution | Institution |
| Encryption keys | HES FinTech / provider KMS | Institution |
| Network controls | HES FinTech | Institution |
| Backups and restore testing | HES FinTech | Institution |
| Security monitoring and alerting | HES FinTech | Institution (with HES guidance) |
| Incident response | Joint | Institution (with HES support) |
| Regulatory compliance of lending activity | Institution | Institution |
Deployment models
HES LoanBox runs on AWS or Google Cloud as a managed deployment, on-premises inside the institution’s own infrastructure, or as a hybrid of the two. The choice affects who operates each control in the table above. Deployment-specific details, such as cloud region, tenancy model, and network topology, are set during onboarding.
Compliance posture
HES FinTech maintains ISO 27001 certification, aligns its controls with SOC 2, and aligns its security program with the NIST Cybersecurity Framework. The platform is configured to the privacy regime of the institution’s market — GDPR, UK DPA, CCPA, PIPEDA, the Australian Privacy Act, and Saudi PDPL among them — through configurable controls and auditable records. Read more on this on the Compliance and secure development page.
Note