|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|Background
Cybersecurity, data privacy, and data protection are critical to our business. In the ordinary course of our business, we collect and store certain confidential information, including personal information from customers, homebuyers and borrowers, and information about our employees, contractors, vendors, suppliers, and third parties. Our Financial Services business relies heavily on the secure processing, storage, and transmission of sensitive and confidential financial, personal, and other information. We maintain an information security program aligned with the NIST Cybersecurity Framework, which includes policies, procedures, and controls designed to protect data and support system availability. Our information security practices include development, implementation, and improvement of technologies, policies, and procedures to safeguard information and support availability of critical data and systems. Independent third parties periodically assess our program and incident response readiness.
Risk Management and Strategy
Cybersecurity risk management is integrated into our enterprise risk framework and decision-making processes. Our cybersecurity risk management program is designed to comply with applicable laws and regulations and to mitigate risks that could materially impact our business. Our information security and IT teams continuously evaluate and address cybersecurity risks in alignment with business objectives. We use the NIST Cybersecurity Framework’s five core functions: identify, protect, detect, respond, and recover, to guide risk management. We also assess materiality of incidents in accordance with SEC disclosure requirements.
Use of Consultants and Advisors
We engage external cybersecurity experts and legal counsel to evaluate and test our risk management systems and maintain compliance. Since 2022, we have retained a CISO-level advisor from a global cybersecurity firm to provide strategic guidance, review policies, and assess our ability to prevent and respond to cyber incidents. We also retain specialized legal counsel for data security and privacy compliance.
In 2025, a global cybersecurity firm conducted a Security Posture Assessment, reviewing policies, procedures, and prior assessments. We implemented recognized best practices and solutions to address findings and strengthen our security posture. We conduct regular tabletop exercises to test incident response capabilities. We also engage third-party vendors for risk assessments, business impact analysis, cloud audits, and remediation.
The Company primarily manages risks for cybersecurity threats associated with its third-party service providers through evaluations and assessments during vendor selection, contract negotiations and contract renewals. We have introduced a third-party vendor risk management solution and professional service to survey and monitor the Company’s critical vendors at on-boarding and on a reoccurring basis.
Our information security team maintains Company policies related to information security for all employees. We have retained a third-party vendor to provide regular security information training, which includes online awareness training modules for our employees on important topics such as spoof login, impersonation attack, identity theft, stolen laptop, and passwords, as well as training on phishing awareness through the routine deployment of phishing simulations.
We have not experienced any cybersecurity incidents that have materially impacted or are reasonably likely to materially impact our business operations, operating results, or financial condition.
Maintaining a robust information security system is an ongoing priority for us and we plan to continue to identify and evaluate new, emerging risks to data protection and cybersecurity both within our Company and through our engagement of third-party service providers.
If we were to experience a material cybersecurity incident in the future, such incident may have an adverse effect, including on our business operations, operating results, or financial condition. For more information regarding these cybersecurity risks and potential related impacts on us, see “Risk Factors” in Part I, Item 1A of this Annual Report on Form 10-K.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Risk Management and Strategy
Cybersecurity risk management is integrated into our enterprise risk framework and decision-making processes. Our cybersecurity risk management program is designed to comply with applicable laws and regulations and to mitigate risks that could materially impact our business. Our information security and IT teams continuously evaluate and address cybersecurity risks in alignment with business objectives. We use the NIST Cybersecurity Framework’s five core functions: identify, protect, detect, respond, and recover, to guide risk management. We also assess materiality of incidents in accordance with SEC disclosure requirements.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|We have not experienced any cybersecurity incidents that have materially impacted or are reasonably likely to materially impact our business operations, operating results, or financial condition.
Maintaining a robust information security system is an ongoing priority for us and we plan to continue to identify and evaluate new, emerging risks to data protection and cybersecurity both within our Company and through our engagement of third-party service providers.
If we were to experience a material cybersecurity incident in the future, such incident may have an adverse effect, including on our business operations, operating results, or financial condition. For more information regarding these cybersecurity risks and potential related impacts on us, see “Risk Factors” in Part I, Item 1A of this Annual Report on Form 10-K.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Board of Directors is aware of the critical nature of managing risks associated with cybersecurity threats.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board of Directors has delegated to the Audit Committee the responsibility to oversee our cybersecurity efforts and cyber-related risks. The Audit Committee, comprised fully of independent directors, is responsible for oversight of our (i) information security policies, including periodic assessment of risk of information security breach, training programs, significant threat changes and vulnerabilities and monitoring metrics and (ii) effectiveness of information security policy implementation.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our CIO and members of management meet with the Audit Committee on a regular basis to review and discuss risk exposure related to our IT systems and data privacy. The purpose of these management updates is to inform the Audit Committee of potential risks related to our IT systems and data privacy, as well as any relevant mitigation or remediation tactics being implemented. The management team and/or Audit Committee, in turn, regularly provide data protection and cybersecurity reports to the full Board of Directors.
The Audit Committee is composed of members with diverse expertise including risk management, technology, and finance. Although none of the members of the Audit Committee have any work experience, degree, or certifications related to information security or cybersecurity, the Audit Committee relies on our CIO and independent feedback from outside advisors on the current and future cybersecurity program to assist the Audit Committee in its cybersecurity oversight responsibilities. Because the method and sources of cyberattacks change frequently, our outside advisors provide invaluable, ongoing updates to inform and educate our Board of Directors on current trends of cybersecurity threats, emerging trends, and best practices.
|Cybersecurity Risk Role of Management [Text Block]
|Role of Management
Our information security team is responsible for implementing and operating our Cybersecurity Risk Management program. Our Chief Information Officer (CIO) oversees the Cybersecurity Risk Management program and reports to the Corporate General Counsel.
Our CIO has extensive IT leadership experience, with more than 20 years of experience in the homebuilding industry and regularly briefs senior management and the Audit Committee on cybersecurity risks and initiatives.
We are a member of the Center for Internet Security (CIS), which assists our management in policy and technical support. Some of the benefits of our CIS membership include direct access to cybersecurity advisories and alerts, vulnerability assessments and incident response for entities experiencing a cyber threat, secure information sharing through the Homeland Security Information Network (HISN) portal, tabletop exercises, and weekly malicious domains/IP reports.
Our CIO regularly informs the Executive Chairman, Chief Executive Officer, Corporate General Counsel, and Chief Financial Officer, of aspects related to cybersecurity risks and incidents. This ensures that the highest levels of management are kept abreast of the cybersecurity posture and potential risks we are facing.
Our CIO and the other members of senior management play a key role in informing the Audit Committee on cybersecurity risks. They provide comprehensive briefings to the Audit Committee on a regular basis, at least twice annually. These briefings encompass a broad range of topics, including emerging threats, status of ongoing cybersecurity initiatives and strategies, incident reports, and updates regarding compliance with regulatory requirements and industry standards.
In addition to our scheduled meetings, the Audit Committee, CIO and other members of senior management maintain an ongoing dialogue regarding emerging or potential cybersecurity risks. Together, they receive updates on any significant developments in the cybersecurity field, ensuring the Board’s oversight is proactive and responsive. Senior management actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives, and is involved in incident materiality determinations that would trigger cybersecurity incident disclosure obligations. This active involvement ensures that cybersecurity considerations are integrated into our broader strategic objectives
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our information security team is responsible for implementing and operating our Cybersecurity Risk Management program. Our Chief Information Officer (CIO) oversees the Cybersecurity Risk Management program and reports to the Corporate General Counsel.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our CIO has extensive IT leadership experience, with more than 20 years of experience in the homebuilding industry and regularly briefs senior management and the Audit Committee on cybersecurity risks and initiatives.
We are a member of the Center for Internet Security (CIS), which assists our management in policy and technical support. Some of the benefits of our CIS membership include direct access to cybersecurity advisories and alerts, vulnerability assessments and incident response for entities experiencing a cyber threat, secure information sharing through the Homeland Security Information Network (HISN) portal, tabletop exercises, and weekly malicious domains/IP reports.
Our CIO regularly informs the Executive Chairman, Chief Executive Officer, Corporate General Counsel, and Chief Financial Officer, of aspects related to cybersecurity risks and incidents. This ensures that the highest levels of management are kept abreast of the cybersecurity posture and potential risks we are facing.
Our CIO and the other members of senior management play a key role in informing the Audit Committee on cybersecurity risks. They provide comprehensive briefings to the Audit Committee on a regular basis, at least twice annually. These briefings encompass a broad range of topics, including emerging threats, status of ongoing cybersecurity initiatives and strategies, incident reports, and updates regarding compliance with regulatory requirements and industry standards.
In addition to our scheduled meetings, the Audit Committee, CIO and other members of senior management maintain an ongoing dialogue regarding emerging or potential cybersecurity risks. Together, they receive updates on any significant developments in the cybersecurity field, ensuring the Board’s oversight is proactive and responsive. Senior management actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives, and is involved in incident materiality determinations that would trigger cybersecurity incident disclosure obligations. This active involvement ensures that cybersecurity considerations are integrated into our broader strategic objectives
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our CIO and members of management meet with the Audit Committee on a regular basis to review and discuss risk exposure related to our IT systems and data privacy. The purpose of these management updates is to inform the Audit Committee of potential risks related to our IT systems and data privacy, as well as any relevant mitigation or remediation tactics being implemented. The management team and/or Audit Committee, in turn, regularly provide data protection and cybersecurity reports to the full Board of Directors.
The Audit Committee is composed of members with diverse expertise including risk management, technology, and finance. Although none of the members of the Audit Committee have any work experience, degree, or certifications related to information security or cybersecurity, the Audit Committee relies on our CIO and independent feedback from outside advisors on the current and future cybersecurity program to assist the Audit Committee in its cybersecurity oversight responsibilities. Because the method and sources of cyberattacks change frequently, our outside advisors provide invaluable, ongoing updates to inform and educate our Board of Directors on current trends of cybersecurity threats, emerging trends, and best practices.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef