Trust Center

Security Built Into the appTRAKER Environment

Layered security controls across applications, infrastructure, access, monitoring and operations protect sensitive lending systems and information.

A guarded gate in front of server racks, protecting the systems behind it

Identity and access

LAUNCHER protects appTRAKER through layered safeguards across people, access, applications, infrastructure and operations. The controls are designed to reduce risk, limit unnecessary access, detect problems and support a disciplined response.

Access is based on business need and role. LAUNCHER uses:

Centralized identity controls
Multifactor authentication where applicable
Least-privilege administration
Periodic access reviews

appTRAKER customers can assign permissions according to user responsibilities.

Application and infrastructure protection

appTRAKER operates in Amazon Web Services with:

Encryption for data in transit and at rest
Network protections and controlled administrative access
AWS Web Application Firewall for internet-facing services
Monitoring across critical infrastructure

Critical information is protected through encryption at rest, and applicable data transmissions use TLS or other approved encryption technologies.

Secure development and change control

LAUNCHER uses documented development, review, testing and release practices. Changes move through controlled environments and approval processes before production deployment.

Testing and vulnerability management

LAUNCHER engages independent third parties for regular penetration testing and vulnerability scanning. Vulnerability identification and remediation are handled through established security and operational procedures.

Monitoring and accountability

System and administrative activity is logged and monitored according to its purpose and risk. Alerts help the team investigate unusual conditions, operational failures and potential security events.

Audit records also support customer due diligence and independent examination.

People and vendors

Security responsibilities extend beyond technology. Personnel receive security awareness training and are subject to access and confidentiality requirements.

Third parties are evaluated according to the services and data involved, with contractual and operational controls applied where appropriate.

Incident response

LAUNCHER maintains a documented incident-response process covering identification, escalation, containment, investigation, recovery and communication. Customer notification follows applicable contractual and legal requirements.

Independent assurance

LAUNCHER has undergone annual SOC 2 examinations since 2023, with Type 2 examinations beginning in 2024, covering Security and Confidentiality controls relevant to the appTRAKER service.

Reports and supporting due-diligence materials are available to qualified customers and prospects through the SOC 2 and vendor due-diligence process.

Related Trust information

Frequently asked questions about appTRAKER security

Where is appTRAKER hosted?

appTRAKER is hosted on Amazon Web Services.

Is appTRAKER data encrypted?

Critical information is protected through encryption at rest, and applicable data transmissions use TLS or other approved encryption technologies.

Does LAUNCHER support multi-factor authentication?

Yes. Multifactor authentication is used where applicable, alongside centralized identity controls, least-privilege administration and periodic access reviews.

Does LAUNCHER perform penetration testing?

Yes. Independent third-party penetration testing and vulnerability scanning are performed on a regular, recurring basis.

Does LAUNCHER monitor the appTRAKER environment?

Yes. LAUNCHER maintains monitoring and alerting across critical infrastructure and security systems.

Does LAUNCHER maintain an incident-response program?

Yes. LAUNCHER maintains a documented incident-response process covering identification, escalation, containment, investigation, recovery and communication.

Does LAUNCHER undergo SOC 2 Type 2 examinations?

LAUNCHER has undergone annual SOC 2 examinations since 2023, with Type 2 examinations beginning in 2024, covering the Security and Confidentiality Trust Services Categories.

Does LAUNCHER provide security documentation?

Yes. Appropriate materials can be shared with qualified customers and prospects, subject to confidentiality and access controls, through the Trust Center and the due-diligence process.

Let’s talk

Request security information

Evaluation teams can request the security, SOC 2 and vendor-review materials their institution requires.