Trust Center

Supporting Bank and Credit Union Vendor Review

Corporate, security, insurance, contractual and operational information for financial institutions evaluating LAUNCHER.SOLUTIONS and appTRAKER.

A completed due diligence checklist handed to a bank for vendor review

Built for the institution review process

Banks and credit unions perform extensive due diligence before engaging technology providers.

LAUNCHER.SOLUTIONS works with Vendor Management, Third-Party Risk Management (TPRM), Information Security, Compliance, Legal, Procurement and Technology teams throughout that process.

Corporate information

LAUNCHER.SOLUTIONS, Inc. is a privately held Delaware corporation providing lending technology to financial institutions and finance companies.

Launcher has operated since 2016 and registered as a Delaware corporation.

SOC 2 and security

Launcher maintains a formal information-security program supporting appTRAKER and an ongoing SOC 2 Type 2 program covering Security and Confidentiality. The latest completed SOC 2 Type 2 report is available under confidentiality requirements.

Due-diligence reviews can address:

Data protection
Encryption
Access controls
Authentication
Vulnerability management
Penetration testing
Security monitoring
Incident response
Backup and recovery
Third-party risk management

Explore SOC 2, security and data protection.

Contractual commitments

Launcher uses a formal SaaS Master Agreement to define responsibilities between Launcher and its customers. The agreement and service-level provisions address:

Scope of services
Customer-data ownership
Confidentiality
Information-security obligations
Data protection
Security incident notification
Backup requirements
Cross-region data replication
Business continuity and recovery commitments
Service availability
Maintenance and updates
Customer support
Issue prioritization and escalation
Data disposition following termination

Specific commitments are governed by the customer agreement and may be adapted to customer requirements.

Insurance

Launcher maintains insurance supporting its SaaS and technology operations. Coverage includes:

Commercial General Liability
Workers Compensation and Employers Liability
Professional Liability
Technology Errors and Omissions
Cyber liability
Privacy and security liability

RFI and third-party risk reviews

Launcher participates in formal financial-institution technology evaluations, including:

Requests for Information (RFI)
Requests for Proposal (RFP)
Vendor due-diligence questionnaires
Third-Party Risk Management (TPRM) assessments
Information security questionnaires
Cybersecurity assessments
Privacy and data protection questionnaires
Business continuity and resilience questionnaires
SOC 2 reviews
Insurance verification
Contract and SLA reviews
Follow-up reviews from Risk, Compliance, Legal, Security and Technology teams

Launcher completes institution-specific questionnaires and responds to the follow-up reviews that accompany them.

Public trust and controlled due diligence

The Trust Center provides public information about Launcher controls and practices. More sensitive material is provided through the due-diligence process.

Published in the Trust Center

SOC 2 program overview, security, data protection, availability, compliance and privacy information.

Provided under due diligence

SOC 2 Type 2 report, Certificate of Insurance, corporate documentation, RFI and questionnaire responses, contract and SLA review.

Internal security policies, Incident Response plans, Business Continuity plans, Disaster Recovery plans and detailed operating procedures remain controlled documents.

Make vendor review easier

Vendor review is part of working with regulated financial institutions. Launcher works directly with Vendor Management, TPRM, Information Security, Compliance, Legal, Procurement and Technology teams to support evaluation of LAUNCHER.SOLUTIONS and appTRAKER.

Evaluate the organization. Review the controls. Understand the commitments. Complete your due diligence.

Frequently asked questions

Can Launcher complete our RFI or vendor due-diligence questionnaire?

Yes. Launcher completes Requests for Information, vendor due-diligence questionnaires, TPRM assessments, information-security questionnaires, cybersecurity reviews and related evaluations for financial institutions.

Can we obtain Launcher’s SOC 2 Type 2 report?

Yes. The latest completed report is available under confidentiality requirements.

Can we obtain a Certificate of Insurance?

Yes. Current insurance documentation is available through the due-diligence process.

Can we review Launcher’s Business Continuity or Disaster Recovery plans?

Detailed BCP and disaster-recovery plans remain controlled. Service-continuity, backup, recovery, availability and related commitments are addressed through the SaaS Master Agreement and SLA, and supporting evidence is available through the due-diligence process.

Does the Master Agreement address security incidents?

Yes. The SaaS Master Agreement addresses protection of customer information, security incidents, customer notification, investigation, corrective action, mitigation and cooperation.

Can our legal team review the Master Agreement and SLA?

Yes. Contractual and service-level provisions are provided during the contracting process.

Let’s talk

Complete your due diligence.

Request corporate, security, insurance and contractual information for your vendor review.