Technology

Security, Privacy, and Data Protection

Protecting sensitive consumer and client data according to industry standards is a core responsibility of our organization. We maintain a structured information security program designed to safeguard the confidentiality, integrity, and availability of the information entrusted to us. Our security practices incorporate administrative, technical, and physical safeguards aligned with regulatory expectations applicable to financial services organizations.

Our security practices support regulatory expectations including the GLBA Safeguards Rule, CFPB service provider expectations, Regulation F, and applicable state financial regulatory requirements.

Security Practices Snapshot

Access Controls System access is restricted based on job responsibilities and business need.
Encrypted Data Transmission Sensitive data is encrypted during transmission using secure protocols.
Endpoint Protection Workstations and servers are protected with endpoint security and malware defense.
Incident Response Procedures Documented procedures exist to respond to and manage security incidents.
Network Security Monitoring Network traffic and security events are monitored for suspicious activity.
Penetration Testing Periodic penetration testing is performed to evaluate system security.
Security Awareness Training Personnel receive ongoing security and data protection training.
Third-Party Risk Management Vendors are evaluated through a structured risk management program.
Vulnerability Scanning Independent vulnerability scans are conducted to identify potential security weaknesses.

Security Program Overview

Information Security Program

Our information security program establishes governance and oversight for protecting systems and data used to support our services in a Zero-Trust environment. Key elements include:

  • Documented security policies and procedures
  • Periodic security risk assessments
  • Security awareness training for personnel
  • Incident response and breach notification procedures
  • Oversight of vendor and third-party security practices
  • Reviews with Leadership

Data Protection

We implement layered safeguards designed to protect sensitive consumer and client information. Security practices include:

  • Encryption of sensitive data at rest & in transit
  • Secure authentication and access controls
  • Network monitoring and intrusion protection
  • Endpoint protection and malware defense
  • Secure data handling and retention procedures

Security Testing & Monitoring

Security controls are regularly evaluated through monitoring and testing activities designed to identify potential risks. These activities include:

  • Independent vulnerability scanning
  • Periodic penetration testing
  • Security configuration management
  • Patch and vulnerability management processes
  • System logging and monitoring
  • PCI-DSS compliant

Third-Party Risk Management

We maintain a structured third-party risk management program to evaluate vendors and service providers that support our operations. Our process includes:

  • Security due diligence prior to onboarding
  • Risk classification based on services and data access
  • Review of available assurance reports where applicable
  • Periodic reassessment of higher-risk vendors
  • Ongoing monitoring of vendor security posture

Privacy & Confidentiality

We are committed to protecting consumer privacy and handling information responsibly. Our practices include:

  • Limiting access to sensitive information based on business need
  • Maintaining confidentiality obligations for personnel and service providers
  • Secure data disposal procedures
  • Privacy practices aligned with financial-services regulations
  • Data retention and destruction practices designed to ensure information is retained only as long as necessary for business, client and regulatory purposes and securely destroyed when no longer required

Business Continuity and Disaster Recovery

We maintain safeguards designed to support continuity of services and recovery from unexpected disruptions. These safeguards include:

  • Data backup and recovery procedures
  • Infrastructure redundancy where appropriate
  • Incident response and recovery procedures
  • Periodic testing of recovery capabilities
  • Periodic Business Continuity Plan testing

Security Contact

Security inquiries or responsible disclosure reports may be submitted to: security@bass-associates.com

Additional security documentation or vendor security questionnaires may be available to clients or prospective partners upon request and a completed NDA provided by Bass & Associates, PC.