|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Abstract]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Our business is highly dependent on information technology. In the ordinary course of our business, we store sensitive data, including our proprietary business information and that of our business partners, and non-public personally identifiable information of mortgage borrowers, on our networks. The secure maintenance, processing and transmission of this information is critical to our operations. Computer malware, viruses, ransomware and phishing attacks remain widespread and are increasingly sophisticated. We are frequently the target of attempted cyber threats, as are many other organizations within the financial servicing industry. We continuously monitor and develop our information technology networks and infrastructure to help prevent, detect, address and mitigate the risk of unauthorized access, misuse, computer viruses, and other events that could have a security impact. Despite these security measures, our information technology and infrastructure may be vulnerable to attacks by hackers or breached due to employee error, malfeasance or other disruptions. Any such breach could compromise our networks and the information stored there could be accessed, publicly disclosed, lost or stolen. Such access, disclosure or other loss of information could result in legal claims or proceedings, liability under laws that protect the privacy of personal information, regulatory penalties, disruption to our operations or trading activities or damage to our reputation, all of which could have a material adverse effect on our business, results of operations and financial condition. For additional information on these risks, see Item 1A, “Risk Factors”.
We recognize the importance of protecting our information and our information technology systems, and assessing, identifying and managing cybersecurity-related risks have been integrated into our risk management processes. We focus on information technology and cybersecurity measures at both an enterprise-wide operational level and an individual employee level. We have in place various methods and levels of information technology and cybersecurity measures which are aimed at protecting our information and information technology systems to help secure long-term value for our stockholders and other stakeholders. By way of example, these measures include the following:
As part of our commitment to information security and data protection, we have achieved SOC 2 Type II certification in 2024. This certification, issued by an independent third-party auditor, verifies that our security controls meet the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy. The SOC 2 Type II audit evaluates the effectiveness of our cybersecurity and IT controls over an extended period, further validating our commitment to safeguarding sensitive information and maintaining a secure operational environment.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|we store sensitive data, including our proprietary business information and that of our business partners, and non-public personally identifiable information of mortgage borrowers, on our networks. The secure maintenance, processing and transmission of this information is critical to our operations. Computer malware, viruses, ransomware and phishing attacks remain widespread and are increasingly sophisticated. We are frequently the target of attempted cyber threats, as are many other organizations within the financial servicing industry.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|we believe that the risks from identified cybersecurity threats, have not materially affected and are not reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our executive team is responsible for overseeing matters relating to our information technology and cybersecurity risk exposures and the steps our Company takes to monitor and mitigate these risks. The executive team is briefed quarterly or as needed by senior management and the Chief Information Security Officer, or CISO, on cybersecurity matters, or more frequently as the circumstances require. Our Vice President of Technology, who serves as our CISO, oversees data privacy, information technology, and cybersecurity matters. Our CISO has extensive information technology and program management experience, has served in this role for the Company since 2022 and has supported the Company’s information security function since 2017.
To date, we believe that the risks from identified cybersecurity threats, have not materially affected and are not reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our executive team is responsible for overseeing matters relating to our information technology and cybersecurity risk exposures and the steps our Company takes to monitor and mitigate these risks.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The executive team is briefed quarterly or as needed by senior management and the Chief Information Security Officer, or CISO, on cybersecurity matters, or more frequently as the circumstances require. Our Vice President of Technology, who serves as our CISO, oversees data privacy, information technology, and cybersecurity matters.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|false
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our CISO has extensive information technology and program management experience, has served in this role for the Company since 2022 and has supported the Company’s information security function since 2017.
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef