Trust Center

Protecting Sensitive Lending Data

Encryption, access controls, monitoring, testing, retention controls and independently examined security practices protect data throughout the appTRAKER environment.

Data moving from a document into encrypted storage and then into a protected folder

Sensitive data, protected through its lifecycle

appTRAKER processes sensitive lending information including applications, credit data, identity information, documents, communications and transaction data.

LAUNCHER.SOLUTIONS maintains security controls designed to protect that information throughout its lifecycle — from the moment it is collected to the moment it is disposed of.

Your data remains your data

Customers retain rights to their credit applications, customer information, related lending data, models and applicable configuration information maintained within appTRAKER.

Launcher maintains customer information as confidential and accesses it only for authorized purposes associated with providing, supporting, maintaining and improving the service.

Sensitive data receives stronger protection

Launcher maintains formal Data Classification & Handling Guidelines.

Sensitive lender and applicant information — including Social Security numbers, driver’s-license information, credit-bureau data, financial information and other personally identifiable information — is classified as Restricted.

That classification establishes requirements for how information is accessed, transmitted, stored, shared and disposed of.

Encryption at rest and in transit

Critical customer information is protected using encryption throughout the environment. Controls include:

Encryption of critical data at rest
TLS and other approved encryption in transit
Encrypted backup data
Controls protecting cryptographic keys

Protect the data while it moves. Protect it while it is stored.

Access based on business need

Access to sensitive information is restricted to authorized personnel. Launcher maintains controls involving:

Unique user accounts
Role-based access
Privileged-access restrictions
Multi-factor authentication for applicable administrative access
Access approval, provisioning and revocation
Periodic access reviews

Sensitive systems and stored customer data are accessible only where legitimate responsibilities require it.

Continuous security testing

Launcher maintains an ongoing vulnerability-management program, with independent testing performed on a recurring schedule.

Ongoing vulnerability scanning

Third-party vulnerability scanning runs on a regular schedule across the appTRAKER environment.

Independent penetration testing

Third-party penetration testing is performed regularly by an independent firm.

Supporting controls include:

Patch and remediation processes
Security monitoring
Intrusion detection and prevention
Network and firewall controls

Identified security issues are evaluated and tracked through resolution according to the applicable security process.

Retention and secure disposal

appTRAKER customer-data retention is governed by customer-specific contractual requirements.

Launcher maintains controlled processes for archival, retention, purge and disposal of customer information, including appropriate verification before and after applicable purge activities.

Information that is no longer required is subject to secure disposal processes intended to make it unreadable or otherwise unrecoverable.

Incident response

Launcher maintains documented procedures for responding to security incidents.

Incident lifecycle

IdentifyClassifyContainInvestigateRemediateCommunicate

Defined roles, escalation procedures, tracking and response requirements help ensure security events are handled through an established process.

Independent assurance

Launcher maintains an ongoing SOC 2 Type 2 program covering Security and Confidentiality. The independent examination evaluates controls relevant to areas including:

Encryption
Access control
Security monitoring
Vulnerability management and penetration testing
Backup protection
Incident response
Data disposal
Third-party risk

Launcher has been examined annually since 2023. Explore the SOC 2 program.

Data protection throughout the lifecycle

appTRAKER protects sensitive information at every stage of the lending process.

Data lifecycle

CollectTransmitProcessStoreAccessRetainDispose

The objective remains consistent at every stage.

Protect confidentiality. Preserve integrity. Restrict access. Maintain accountability.

Frequently asked questions

Who owns customer data in appTRAKER?

The customer retains its rights to its lending and customer data maintained within appTRAKER.

Is customer data encrypted?

Yes. Critical customer data is encrypted at rest, applicable transmissions are protected through TLS or other approved encryption technologies, and applicable backup data is encrypted.

Who can access customer data?

Access is restricted to authorized personnel with a legitimate business need and is controlled through authentication, permissions, privileged-access controls and periodic reviews.

How long is customer data retained?

Retention is governed by applicable customer contracts and implementation requirements.

Does Launcher perform penetration testing?

Yes. Independent third-party penetration testing and vulnerability scanning are performed on a regular, recurring basis.

Are these controls independently examined?

Yes. Launcher maintains a SOC 2 Type 2 program covering the Security and Confidentiality Trust Services Categories.

Let’s talk

Protecting sensitive lending data.

Request security documentation covering encryption, access control, testing, retention and incident response.