Overview

HES LoanBox is delivered as configurable lending infrastructure that a financial institution runs either in the cloud, managed by HES FinTech, inside its own environment on-premises, or in a hybrid mode. Security is therefore a shared concern rather than a single product feature. The applicable security controls and the division of responsibilities between HES FinTech and the customer depend on the selected deployment model, system configuration, and connected services.

This section explains the platform’s security architecture, how responsibility is divided between HES FinTech and the institution, and how that division shifts with the deployment model.

Security architecture at a glance

HES LoanBox applies controls at distinct layers. Each layer is documented on its own page in this section.

Layer What it covers
Identity Authentication, roles, permissions, password and lockout policy (delegated to Keycloak)
Application and API Encryption, OWASP-category defenses, API authentication, KYC/KYB, anti-fraud
Infrastructure Cloud and on-premises hosting, environments, backups, availability, disaster recovery
Governance Activity logging, traceability, monitoring, incident response
Standards ISO 27001, SOC 2, privacy regulation, NIST alignment, secure development lifecycle

The platform is API-first: every capability is reached through authenticated, role-authorized APIs, and the same access rules apply whether a request comes from the user interface, an agent portal, a borrower portal, or an integration.

Shared responsibility model

Security divides into two parts: the security of the platform, which HES FinTech maintains, and the security of the deployment around it, which is shared with the institution and the cloud provider, in cloud deployments. The table shows where each responsibility sits.

Area Cloud (HES-managed) On-premises (institution-managed)
Physical and data-center security Cloud provider Institution
Operating system and patching HES FinTech Institution
Platform code and updates HES FinTech HES FinTech (release), institution (apply)
Identity configuration (Keycloak realms, roles, policies) Institution Institution
Encryption keys HES FinTech / provider KMS Institution
Network controls HES FinTech Institution
Backups and restore testing HES FinTech Institution
Security monitoring and alerting HES FinTech Institution (with HES guidance)
Incident response Joint Institution (with HES support)
Regulatory compliance of lending activity Institution Institution

Deployment models

HES LoanBox runs on AWS or Google Cloud as a managed deployment, on-premises inside the institution’s own infrastructure, or as a hybrid of the two. The choice affects who operates each control in the table above. Deployment-specific details, such as cloud region, tenancy model, and network topology, are set during onboarding.

Compliance posture

HES FinTech maintains ISO 27001 certification, aligns its controls with SOC 2, and aligns its security program with the NIST Cybersecurity Framework. The platform is configured to the privacy regime of the institution’s market — GDPR, UK DPA, CCPA, PIPEDA, the Australian Privacy Act, and Saudi PDPL among them — through configurable controls and auditable records. Read more on this on the Compliance and secure development page.

Note

The institution remains responsible for the regulatory compliance of its lending decisions and operations. HES LoanBox provides controls that help automate regulatory workflows and keeps records that auditors can review, but it does not assume the institution’s compliance obligation.

Search documentation