Infrastructure and deployment security

This page covers the environments HES LoanBox runs in, the controls around them, and how availability, backups, and disaster recovery are handled across cloud and on-premises deployments. Which party operates each control depends on the deployment model described in the Overview.

Cloud providers and hosting

Managed deployments run on AWS or Google Cloud. Both providers operate physically secured, independently audited data centers, and the platform inherits their infrastructure-level controls. Institutions that require it can instead run HES LoanBox on-premises inside their own data center or in a hybrid arrangement. Data residency in a specific region can be provided to meet the client’s requirements if the cloud provider has data centers there.

Environments

Work is separated across environments so that changes are tested before they reach production.

Environment Purpose
Development Active development and internal testing
Staging / UAT Pre-production validation and customer acceptance testing
Production Live system serving borrowers and staff

Changes are promoted through these environments via the release pipeline. Production data is not used unmodified in lower environments.

Network security

Network controls limit exposure to the minimum needed to run the service: network segmentation, firewall and security-group rules, private networking between components, and provider-level protection against volumetric attacks. Baseline DDoS protection is provided by the underlying cloud platform. Additional managed DDoS protection can be enabled depending on the deployment requirements. External web traffic can be fronted by a web application firewall.

Backups

Backups are automated and encrypted, with full backups performed once a day by default. In cloud deployments, the provider also performs incremental backups throughout the day to support point-in-time recovery (PITR). The default retention period is one week but can be adjusted to meet each client’s retention policy. Restores are tested to verify that backups are recoverable.

Availability and resilience

Managed deployments use redundancy across the hosting infrastructure and are monitored for availability. In an on-premises deployment, availability depends on the institution’s own infrastructure and operations.

Disaster recovery

As part of the SLA, a disaster-recovery plan covers restoring service after a major failure — backup restoration, failover, and defined recovery objectives.

Note

In on-premises deployments, physical, network, backup, and availability controls are owned by the institution. HES FinTech provides the platform, its update path, and operational guidance.

Search documentation