Security & Privacy Practices
How PhilaLoan should handle forms, scripts and sensitive information.
Security approach
PhilaLoan is designed to minimize sensitive-data exposure, keep private runtime data outside normal public access and separate informational pages from any configured request flow. HTTPS, strong administrator credentials and restricted server access are baseline deployment controls.
Sensitive information
Users should not send Social Security numbers, online-banking passwords, payment-card credentials or similar secrets through a generic contact channel. A third-party financial form should collect only the information required for its configured purpose and should be clearly identified.
Reporting a security issue
The production security.txt record provides the designated security contact and policy location. Security reports should include enough technical detail to reproduce the issue without publishing sensitive user data.
External references
The policy context for this page is checked against Federal Trade Commission — Privacy and Security. Production-specific data flows, recipients, consent text, retention and security controls must still match the deployed site.
Accountability in practice
This information is tied to the operating and editorial process described on the site. Named roles, commercial relationships, review methods and security statements should match the current production configuration rather than a generic trust template.
When this page changes
Update the page when the responsible team, workflow, methodology, commercial relationship or supporting evidence changes materially. Keep the effective date and the reason for important corrections visible where they affect consumers.
Who wrote and reviewed this page
The primary author is shown separately from the editor, fact-checker and financial reviewer so each responsibility is explicit.
Lorraine RoberteLead Writer — Loans & Consumer FinanceIntent, clarity, disclosures and editorial consistencyFact-checked by
Timothy Moore, CFEI®Fact-Checker & Financial Education ReviewFacts, dates, source fit and factual consistencyAffordability reviewed by
Laura Gariepy, MBAConsumer Finance ReviewerRates, costs, repayment examples and affordability contextDecision details that can change the answer
Open only the topics that apply to your situation. Each module focuses on a different cost, timing, income, repayment, eligibility or provider question.
Related decisionSecurityExplore
Understand PhilaLoan’s public security principles, the limits of what can be disclosed, and how to report a security concern.
PhilaLoan is designed to minimize sensitive-data exposure, keep private runtime data outside normal public access and separate informational pages from any configured request flow. HTTPS, strong administrator credentials and restricted server access are baseline deployment controls.
Users should not send Social Security numbers, online-banking passwords, payment-card credentials or similar secrets through a generic contact channel. A third-party financial form should collect only the information required for its configured purpose and should be clearly identified.
