Skip to content

Security

What bank IT needs to know about KohltSoft

Bank IT teams have a standard set of questions before approving any software vendor. This page answers them directly. If you have additional questions or need documentation for a vendor security review, contact us.

Security posture

Data encrypted in transit and at rest

All data transmitted between your users and KohltSoft is encrypted via TLS. Case records, letters, and supporting documents are encrypted at rest in cloud storage.

Role-based access control

Access is governed by role. Operations staff see their assigned cases and queue. Managers see the full queue and can assign work. Audit staff have read-only access to the complete case timeline and evidence package.

Cloud-hosted infrastructure

KohltSoft runs on cloud infrastructure with high availability and automated backups. Data is retained according to configurable retention policies aligned to your bank's record retention requirements.

Audit log for all system actions

Every action taken in the system — case creation, letter generation, provisional credit entry, status changes — is logged with a timestamp and the identity of the user who performed the action.

No core system integration required

KohltSoft does not connect to your core banking system. It is not a core module or plugin. There is no API integration, no data feed, and no system access to your core. IT deployment is a user provisioning exercise, not an integration project.

What data KohltSoft stores

KohltSoft stores Reg E case records: dispute intake data, investigation notes, required letters, provisional credit records, and case timelines. This data is entered by your staff through the KohltSoft interface — it is not pulled from your core banking system.

Data stored in KohltSoft

  • Consumer dispute intake records (name, account reference, dispute details)
  • Transaction information entered by staff during case intake
  • Investigation notes and supporting documents uploaded by staff
  • Generated letters and proof of send
  • Provisional credit amounts, dates, and decisions
  • Case action history with timestamps and user identifiers

Need documentation for your vendor review?

If your IT or compliance team needs a security questionnaire, data handling documentation, or a vendor review meeting, contact us directly.

Contact for Security Review