Documented Security Program
Policies, procedures, technical controls, and security-management practices support key areas of the platform and operating environment.
Policies · Procedures · Controls
SECURITY & TRUST
Decipher maintains a security program designed to support the security needs of commercial lenders and financial institutions. Our approach combines AWS cloud infrastructure with encryption, access controls, security monitoring, documented policies, vulnerability management, and ongoing testing.
DATA SECURITY & PROTECTION
Decipher's security program is supported by technical controls, monitoring, documented policies, testing, and risk-management practices designed for a commercial lending environment.
Decipher is hosted on Amazon Web Services (AWS), with security controls and configurations applied to its cloud environment, application, and data.
Role-based access controls and user-level permissions help limit access based on authorized roles and responsibilities. Activity logging provides visibility into system and user activity.
Decipher maintains security monitoring and vulnerability-management practices designed to help identify and respond to potential security issues. The program includes SIEM-enabled monitoring and recurring independent penetration testing.
Decipher maintains documented security policies, procedures, and supporting materials covering key areas of its security program. Relevant documentation is made available as part of their security and vendor due-diligence process, subject to applicable confidentiality requirements.
Controls and practices supporting the Decipher environment
SECURITY ASSURANCE & DUE DILIGENCE
Banks and commercial lenders routinely conduct detailed security and vendor-risk reviews of the technology providers they use. Decipher supports these reviews with security questionnaires, policies, testing information, and other relevant documentation for qualified clients and prospects.
Policies, procedures, technical controls, and security-management practices support key areas of the platform and operating environment.
Policies · Procedures · Controls
Recurring penetration testing by an independent security provider helps identify potential vulnerabilities and areas to strengthen.
Third-Party Penetration Testing
Decipher regularly supports bank and lender security/vendor-risk reviews and provides relevant documentation directly to qualified clients and prospects during diligence.
Client & Prospect Due Diligence
SECURITY INFORMATION
Qualified clients and prospects can request additional information about Decipher's security practices, controls, testing, and supporting documentation as part of their security or vendor due-diligence process.
Contact Our Team