Security
Data Security
What we hold.
Names, addresses, telephone numbers, account balances and payment history — and, on healthcare placements, information that is protected health information. Card data is tokenized at the gateway and never stored by us in raw form.
GLBA · 15 U.S.C. § 6801 et seq.What the law requires.
The Safeguards Rule requires a written information security program with named accountability, a risk assessment, access controls, encryption, vendor oversight and an incident response plan. It is a program requirement, not a checklist of products.
16 C.F.R. Part 314 · GLBAHow we work inside it.
Access is granted by role and by business need, logged, and revoked promptly when someone leaves. Data is encrypted in transit and at rest. Retention is bounded by schedule and destruction is documented. Vendors that touch consumer data are held to the same standard and audited.
16 C.F.R. § 314.4 · § 682.3 · CFPB Bulletin 2016-02Why it matters here.
A collection file is one of the more sensitive records a consumer has, and it is assembled from data they did not choose to give us. Protecting it is the price of holding it.
Compliance
Security Controls
| Control | Governing authority | Status |
|---|---|---|
| Written information security program with named accountability | 16 C.F.R. § 314.4(a) | Maintained |
| Risk assessment performed and updated | 16 C.F.R. § 314.4(b) | Maintained |
| Data encrypted in transit and at rest | 16 C.F.R. § 314.4(c)(3) | Enforced |
| Multi-factor authentication on all platforms | 16 C.F.R. § 314.4(c)(5) | Enforced |
| Access granted by role and business need, reviewed periodically | 16 C.F.R. § 314.4(c)(1) | Enforced |
| Access logged, and revoked promptly on termination | 16 C.F.R. § 314.4(c)(1) | Logged |
| Workstations locked on a short idle timeout; no consumer data on portable media | Internal control per our furnisher policy | Enforced |
| Card data tokenized at the gateway, never stored in raw form | PCI DSS | Enforced |
| Retention bounded by schedule, with documented secure destruction | 16 C.F.R. § 682.3 | Scheduled |
| Physical records in controlled storage; documents shredded, not discarded | 16 C.F.R. § 682.3 | Enforced |
| Vendors and service providers subject to due diligence and monitoring | 16 C.F.R. § 314.4(f) · CFPB Bulletin 2016-02 | Audited |
| Documented incident response plan, with backup restores tested | 16 C.F.R. § 314.4(h) | Tested |
| Disaster recovery plan with documented recovery objectives | Internal continuity program | Maintained |
| PHI handled under a business associate agreement where one applies | 45 C.F.R. Parts 160, 164 | Per engagement |
| State data-security and breach-notification requirements applied | State data-protection statutes | Per matrix |
What we do not claim
We do not hold a SOC 2 report and we do not describe ourselves as certified against a standard we have not been audited against. Where a client requires an independent assessment, we support theirs. What is listed above is what we operate, and it is what we can evidence.
Related
Additional Information
Privacy, compliance and consumer rights
What we collect and why is in our Privacy Policy. The full regulatory framework and our licensing are on the Compliance page. What a consumer can ask us to do — including deleting a phone number or disputing an account — is on Consumer Rights.