Security & Compliance at Vergent LMS

Security That Regulators Trust

Vergent LMS is SOC 1 Type II and SOC 2 Type II certified and with clients including the FDIC, serving 20,000+ daily users.

Request A Demo

Built for Lenders Who Answer to Examiners

When your platform has to satisfy examiners, the bar is different. Vergent LMS serves lenders who answer to examiners — installment lenders, consumer finance companies, and other regulated lenders — and the platform is built to hold up under that scrutiny.

Certified Controls, Independently Audited

Vergent LMS is SOC 1 Type II and SOC 2 Type II certified. Type II reports don’t evaluate a moment in time — they verify that our controls operate effectively over a sustained audit period, examined by an independent auditor.

Compliance isn’t bolted on, either: lending rules, disclosures, and limits are configurable state by state, across all 50 states.

SOC 1 & SOC 2 Type II

Certified controls, examined by an independent auditor over a sustained audit period.

Clients Include the FDIC

The FDIC is a current Vergent client.

20,000+ Daily Users

Lenders across the country run their daily operations on Vergent.

$690B in Loans Serviced

Enterprise scale, with compliance configurable across all 50 states.

Security That Keeps Pace With the Threat Landscape

Lenders operate in a continuously changing security environment — evolving data and network threats on one side, new compliance requirements and business mandates on the other. Meeting that bar takes more than a firewall: it takes proactive protection against breaches, redundant infrastructure, dependable backups, and controls that hold up to independent audit.

Vergent approaches security as a discipline, not a checkbox — combining experienced security professionals, established best practices, and best-of-breed technology partners to keep the platform secure, available, and operating in compliance with applicable regulations.

Available When Your Business Needs It

Vergent is hosted on Microsoft Azure with redundant infrastructure and availability options designed for business continuity, and all data is stored in the United States. System backups are redundant and managed through the Azure cloud. Platform updates ship monthly and are applied seamlessly — no downtime, with release notes delivered a week in advance. Current availability statistics are provided during vendor review rather than published here, so the numbers your team evaluates are always the real, current ones.

A Shared Security Model Your IT Team Will Recognize

Vergent carries: SOC 1 Type II and SOC 2 Type II audit obligations, PCI DSS compliance, platform patching and monitoring, hosting and infrastructure management, and compliance-driven platform updates.

Your team keeps: control of user roles and permissions, SSO and Active Directory integration, IP-based access restrictions, and change control over configuration and integrations — the security decisions that should stay inside your walls.

Frequently Asked Questions

Is Vergent LMS SOC 2 certified?

Yes. Vergent LMS is SOC 1 Type II and SOC 2 Type II certified — an independent auditor has verified that our controls operate effectively over a sustained period.

Does the FDIC use Vergent LMS?

Yes. The FDIC is a current Vergent client. We do not discuss the scope or terms of any client engagement.

Is Vergent secure enough for a regulated lender?

Vergent serves regulated lenders nationwide. The platform is SOC 1 Type II and SOC 2 Type II certified and PCI DSS compliant, and clients include the FDIC.

How does Vergent handle multi-state compliance?

Vergent supports configurable, state-by-state compliance across all 50 states, so lending rules, disclosures, and limits match each state you operate in.

Where is our data hosted?

Vergent is hosted on Microsoft Azure, and all data is stored in the United States.

How is card data handled?

Vergent is PCI DSS compliant. Card data is handled through secure iframes with third-party payment processors — Vergent never stores raw card numbers, and subsequent transactions use tokenized references.

Can we control who accesses the system, and from where?

Yes. Role-based permissions govern every screen and action, SSO and Active Directory integration are supported, and logins can be restricted to approved IP addresses.

How are updates and patches delivered?

Monthly releases are applied seamlessly with no downtime, and release notes arrive a week in advance. SOC reports and SLA specifics are available for your vendor-review process under NDA.

Security Questions? Let’s Answer Them.

Bring your security team — we’re comfortable in that conversation.