| Security and the Loan Origination System (LOS):
All logins for the LOS are secured via industry-standard 128-bit SSL (Secure Sockets Layer) encryption technology.
Our web servers hosting the LOS web sites are enabled with 128-bit strong-encryption SSL Certificates and ensure that any traffic passed between a client and the server are secured via this encryption standard. Users are not permitted to step outside of the HTTPS encryption stream which would allow unsecured transactions to take place.
Back-end communication between the web servers and the database servers is encrypted using Microsoft's NTLMv2 encryption protocol.
A firewall utilizing stateful packet inspection is in place to allow access only to and from the web servers to the public Internet ports. We use NAT (Network Address Translation) to protect the web servers from direct Internet access. Any traffic to the web servers must traverse the inspection rules built into the firewall.
In addition, the web servers are frequently updated with the latest security patches and updates released from Microsoft to ensure that they are not open to known vulnerabilities.
The data entered into the LOS is stored in a secure environment. The data center is located in a 376,000 square foot facility employing manned security, biometric scanners, surveillance cameras, and uses layered authentication controls which allow only authorized individuals physical access to the servers storing LOS related data. |