Security Commitments
High-Level Security Overview
Last Review: January 1, 2025
This overview outlines the core security commitments and principles that Rise Digital Financial Corp and Blink uphold, demonstrating our dedication to protecting our clients' data and maintaining trust.
1. Prioritizing Data Protection
Rise protects user data with encryption at rest and in transit, ensuring sensitive information such as personal details and financial records remains secure from unauthorized access.
2. Robust Access Controls
All system and data access is governed by the principle of least privilege, supported by multi-factor authentication (MFA) wherever possible. Only the personnel who need specific data to do their jobs can access it, and we regularly review and revoke unneeded permissions.
3. Continuous Monitoring & Rapid Response
- Rise deploys monitoring solutions to detect unusual system or application behaviors. Any potential threat triggers automated alerts for our security team.
- An incident response plan is in place, detailing how to contain and remediate breaches swiftly, and how to communicate with affected parties if necessary.
4. Secure Development & Infrastructure
- Blink's applications are developed with secure coding practices and undergo periodic penetration testing to identify and remediate vulnerabilities.
- Our systems are hosted in a secure cloud environment, allowing us to scale as needed while maintaining strict security standards.
5. Compliance with Regulations & Industry Standards
- Rise monitors and aligns with applicable state and federal regulations—especially critical for small-dollar lending.
- Where relevant, we leverage industry best practices, including frameworks such as ISO 27001, NIST SP 800-53, and SOC 2 guidelines, to structure our security and compliance efforts.
Need the Complete Security Policy?
For access to our complete Information Security Policy or to discuss specific security concerns, please contact our security team.