Servicing Director Encryption Overview

Servicing Director Encryption Overview

Finastra takes the security of the Non-Public Personal Information (NPPI) data very seriously. The data security put in place for Servicing Director provides very strong encryption of user credentials. This article includes a brief description of the technology and process used for the encryption, and benefits of implementation.

Servicing Director

Servicing Director uses RC4 encryption with an MD5 message digest algorithm. Encryption is used solely for user credentials. An encryption key is hard-coded in a Servicing Director .dll file and used to encrypt the credentials. User credentials are hashed, encrypted, and stored in a shared memory location that can be accessed when loading different Servicing Director modules, so users do not have to log in again when opening a different module.

Customer Self-Service (CSS)

For borrowers, CSS uses a salted triple DES algorithm to encrypt user credentials in the session string. Salts are stored in the Service database for CSS access. 

For tellers, CSS uses the same encryption method as SD encryption. This is because a teller is actually logging in with credentials created in SD. Borrowers will not be able to log directly log into SD, and will use CSS credentials.

Encryption Technologies

Databases can be encrypted using Microsoft SQL native Transparent Data Encryption (TDE), which offers encryption by the server which hosts the Servicing Director databases. TDE performs real-time encryption and decryption of the data so your Microsoft system administrator can implement it, and control the creation and maintenance of keys and certificates, and our Servicing Director product would not be aware of the encryption.  Use your Microsoft support resources for more information about how to implement and manage TDE. 

If your financial institution desires network transmission encryption, there are many generally available hardware / software solutions your Microsoft system administrator can implement in your environment to provide that encryption / decryption between points of transmissions.  


ArticleNumber:

000053867

    • Related Articles

    • Overview of Construction Loans

      To process construction loans in Servicing Director, you must first set up the system for construction loans as follows: Set up a company to allow construction loans. Set up cost codes and cost code templates. Set up inspections and assign the ...
    • Overview of Task Tracking

      Task Tracking uses task, task rules, projects, and statuses to help users manage workflow in Servicing Director: Tasks: A task is a single unit of work at the loan level, such as Contact borrower or Send letter. A task can be independent (a ...
    • Selecting Servicing Director Fields for Logging

      You can keep a log of changes to specific fields in Servicing Director. This log reports changes from one value to another value for the selected fields. This log does not include the first time a value or data is entered into a blank field and does ...
    • Fusion Servicing Director Technical Kickoff Call Outline

      Fusion Servicing Director Technical Kickoff Call Outline Summary: Introductions, Project Overview, Product Overview, Team Responsibilities and Meeting Wrap Up. Project Overview Technical Call Installation - Base product Installation - CSS and/or ...
    • Reinstalling Servicing Director

      Reinstalling Servicing Director is not often a solution to a problem, but if you should decide to reinstall Servicing Director, consider the following: You must uninstall Servicing Director to reinstall it. You must use the Windows programs list and ...