Audit logging and monitoring

HES LoanBox records user and system activity so that operational and security-relevant actions can be traced, reviewed, and retained for audit. This page covers activity logging, traceability of a loan through its lifecycle, security monitoring, and incident response.

Activity and audit logs

The platform records who did what, when, and to which record. Logged events include:

Category Examples
Authentication Sign-in, sign-out, failed attempts, lockouts (recorded in Keycloak)
Access administration Role assignments and changes, user creation
Loan operations Application decisions, disbursements, write-offs, adjustments, waived fees
Configuration Changes to products, product groups, templates, and settings
API Authenticated API calls against protected endpoints

Records carry a timestamp, the acting user, the action, and the affected entity, and are kept as tracked records for later review.

Traceability

Because each action is attributed, a loan or a credit decision can be traced end to end — who created the application, who verified the data, who decided it, and what the scoring result was at the time. Scoring outputs are retained alongside the decision, so the basis for a decision remains reviewable. These records support audit-ready reconstruction during an examination cycle.

Security monitoring

Platform health and security-relevant events are monitored, with alerting on anomalies. In managed deployments HES FinTech operates continuous monitoring and log aggregation; on-premises, the institution operates it, and logs can be exported into the institution’s own monitoring or SIEM tooling.

Log retention and access

Log retention is configurable to the institution’s policy (otherwise, 1–3 months by default), access to logs is restricted by role, and logs can be exported for the institution’s own systems.

Incident response

HES FinTech maintains an incident-response process covering detection, triage, containment, notification, remediation, and post-incident review. When an incident affects an institution’s deployment, HES FinTech notifies the institution within the agreed timeframe so it can meet its own obligations — including any breach-notification duties its regulators impose, such as the 72-hour notification required under GDPR.

Note

Audit-ready records are kept for the institution’s auditors. Responsibility for regulatory reporting remains with the institution; the platform supplies the records and traceability behind it.

Search documentation