Corporate Governance
We would like to inform you of Hypoport’s developments concerning the Digital Operational Resilience Act (DORA), which has been in effect since the start of 2023. DORA represents a crucial augmentation to the existing frameworks of the Network and Information Systems Directive (NIS2) and the General Data Protection Regulation (GDPR), aiming to enhance the resilience of financial institutions against escalating threats posed by both external adversaries and internal vulnerabilities.
Both the Dutch Authority for the Financial Markets (AFM) and the Dutch Central Bank (DNB) have been appointed with the oversight of ensuring compliance with the stipulations of DORA by the end of 2024. Given that our Dutch clientele operates under the supervision of either the DNB or AFM, there is a consequential impact on the services provided by Hypoport, particularly concerning our PRoMMiSe software. This necessitates a proactive alignment with the regulatory mandates of DORA.
To kick off on a positive note: the necessary groundwork was already laid some years ago, notably through our ISAE 3402 type II certification. This certification, alongside our approach encompassing business continuity management, data & privacy governance and employee training & awareness programs, positions us favourably within the landscape DORA seeks to address. Additionally, our proven track record with the implementation of regulatory mandates such as GDPR has enabled us, in collaboration with our clients, to establish a reliable and regulated operating environment.
Nonetheless, an effort has been made towards the formalization and documentation of certain processes within an ICT Risk Management Framework. This framework, which demands periodic evaluation and refinement, is instrumental in our ongoing efforts to comply with regulatory standards and we are committed to improving and formalizing it.
So far, our control framework has been enhanced with several significant new features, including:
- The introduction of daily vulnerability scans within our source code to proactively identify and address potential security issues.
- A robust logging system that meticulously tracks user activity and the actions of administrators, ensuring a high level of oversight and auditability.
- The deployment of an emergency ‘panic button’ feature designed to quickly contain malware outbreaks or any other unauthorized usage, thereby bolstering our defensive capabilities.
We remain committed to continuous improvement and will persist in expanding and refining our control framework to meet evolving security challenges and regulatory requirements. Through LinkedIn and in reaching out personally with our clients we will keep you updated and involved with our progress. Please do reach out if any questions might arise.
The Hypoport security team
ISAE 3402 Type II
International Standard on Assurance Engagements (ISAE) 3402 ‘Assurance Reports on Controls at a Service Organization’ deals with assurance engagements undertaken by a professional auditor in practice to provide a report that is likely to be relevant to user entities’ internal control as it relates to financial reporting. Both management of the service organization as well as an independent auditor make an assertion about the degree of control. The controls detailed in the ISAE3402 Type II framework aim to ensure Hypoport operates according to its own defined business processes and guidelines when it comes to developing, testing, releasing, maintaining and hosting software solutions to its customers. The processes in scope are:
- Access Management process.
- Change Management process.
- Continuity Management process.
- Incident Management process.
- Vendor Management process.
- Security Management process.
- Hosting management process.
Subservice organisations: ISO 27001 : 2017 / SOC 1 Type II
Most relevant subservice organizations for Hypoport are:
- Quaere: acts as the ICT partner for maintenance of the ICT environment (PC’s, servers, back-up facilities);
- Microsoft Azure: acts as cloud provider for Hypoport’s ‘PRoMMiSe As A Service’ solution and the LoanByLoan platform. The ‘PRoMMiSe As A Service’ solution can be facilitated for customers directly and/or used for the BPO activities.
We have service level agreements in place with these companies, detailing the level of service we agreed on, as well as the timeframe(s) in which we expect those services to be delivered, should we require them. These SLA’s serve as our controls when dealing with these subservice companies. Specific for Microsoft Azure we rely on the SOC 1 Type II report and follow up if needed. Quaere is certified ISO 27001 : 2017 on information security related to supplying and maintaining of workplaces, servers and networks. Delivering of Cloud Services, Server hosting, Website hosting, Internet connections, VoIP and support for customers through their service desk.
The Hypoport Code of Conduct:Â Tech, Teamplay and You.Â
Why does this Code of Conduct exist?Â
This Code of Conduct reflects our shared identity and the standards we pursue in all companies of the Hypoport Group (collectively “Hypoport”). It forms the framework for our further Hypoport compliance regulations and Hypoport principles. The goal: To strengthen the trust of all those associated with Hypoport and to underline our role as a reliable partner. This Code of Conduct is a clear sign of our commitment and integrity. It determines our daily actions here and now and our long-term goals.Â
Hypoport: A force shaping markets
We take responsibility for our actions, remain visionary and cooperative. As shapers of markets and workplaces, we are all challenged every day to demonstrate our special collegiality and innovative spirit. You are encouraged to ensure compliance with the principles of this Code of Conduct. Familiarize yourself with its contents and integrate its principles into your professional actions. Â
Who does the Code of Conduct apply to?
This Code of Conduct applies to everyone at Hypoport: It applies to all companies of the Hypoport Group and at all levels, i.e., to all employees and management alike (collectively “Hypoportler”*).
What you can rely on: Our core values for ethical behavior.Â
- We rely on fairness, transparency, and integrity.Â
- We do our best in all areas of our business.Â
- We treat each other, our customers, business partners, and other stakeholders with respect and goodwill.Â
- We take responsibility for our actions and are aware of our impact on society and the environment. Â
You are in the right place. And important.Â
Promoting diversity: Hypoport’s commitment to fairness, respect, and equal opportunities
The strength of Hypoport lies in our employees. We live an inclusive culture that respects and values every person in their diversity – regardless of role and background. The diversity of our employees is a crucial success factor for us in a complex world. We are committed to a work environment characterized by fairness, respect and equal opportunities and create structures that do justice to this diversity. Â
Actively against discrimination, harassment, and extremism
We do not tolerate any discrimination based on gender, age, origin, sexual orientation, or religious affiliation, disability, or other similar characteristics, nor any harassment, bullying, abuse of power or violence. Our goal is to create a safe and supportive work environment where we, as well as our customers and business partners, can move without fear at all times. This claim goes beyond the workplace at Hypoport: We clearly distance ourselves from political parties, movements, and organizations classified or monitored as extremist by the Office for the Protection of the Constitution.Â
Technology is as ethical as we design it.Â
Data protection
Taking the protection of personal data seriously, prioritizing it, and ensuring its implementation in products and services is crucial for our sustainable success. You are obliged to comply with the relevant data protection regulations and internal data protection policies. We also expect you to participate in the regular internal data protection training of your Hypoport company. Â
Cybersecurity and IT usage
We protect our IT systems and data from unauthorized access and cyber threats. You are obliged to use the IT provided to you responsibly and only within the permissible framework, to comply with internal IT policies, and to participate in the internal IT security training of your Hypoport company. Â
Ethical development and use of AI and automated processes
Observing ethical principles is also an important factor in the development and use of AI and automated processes. We ensure that the AI systems we use operate transparently, fairly, and without bias.Â
Intellectual property, trade secrets, and confidential information
Our business models, products, algorithms as well as processes and their continuous development are crucial for our business success as a technology provider. Accordingly, we are committed to protecting intellectual property, trade secrets and confidential information. We expect you to be aware of the importance of protecting Hypoport’s intellectual property, trade secrets and confidential information, as well as those of our customers and business partners, and to ensure this through appropriate measures. Â
Compliance: Guided by reason and integrity. Â
The ethics of right decisions
Compliance is the responsibility of everyone. You are obliged to make decisions that maintain Hypoport’s integrity. This means that in our daily work, we consider not only the economic efficiency of our actions but also legal requirements and our ethical principles. Our decisions should be understandable, justified and fair.Â
Gifts, benefits and combating corruption
Although gifts and benefits can be part of business relationships, they must never influence business decisions or create the appearance of influence. All gifts, benefits, perks and invitations must be appropriate to their purpose and documented according to our Benefits & Gifts Policy. Hypoport disapproves of any form of corruption and other criminal acts such as extortion, fraud, breach of trust, bribery and corruption. Sponsorship of mega-events and donations to political parties or lobbying associations must be avoided if they serve the purpose of unfair influence.Â
Avoiding conflicts of interest
We expect you to avoid situations where you may have a conflict of interest. This includes your economic and personal activities that may conflict with Hypoport’s interests. This not only affects you but also your relatives, close persons, or organizations with which you are associated. If you still find yourself in a conflict of interest, you are obliged to disclose it transparently and help resolve it.Â
Misuse of company property and expenses
Company property, both material such as office supplies and equipment and immaterial such as working time or intellectual property, is intended exclusively for business purposes. We expect you to respect, protect and use company property responsibly. Use your judgment to ensure that purchases and related expenses are necessary and appropriate for the intended business purpose. Personal expenses may generally not be charged. For expenses and travel costs, please follow the internal regulations of your Hypoport company.  Â
Conducting business lawfully: Always. Â
Legal compliance
We expect you to comply with the relevant legal requirements. Ensuring compliance and keeping yourself informed is the responsibility of each of us. We ensure that you are informed about changes and additions to the applicable compliance regulations, including this Code of Conduct.
Fair competition
We believe in the free market economy and fair competition, as it promotes innovation and brings about effective solutions. We compete ethically and legally and comply with relevant antitrust and competition laws that prevent unfair and/or anti-competitive business practices.
Suppliers and supply chain
Suppliers should only be engaged after careful and fair review regarding technical requirements, economic efficiency and sustainability. You are obliged to follow the Procurement Policy and the Policy on the Involvement of External Parties. Some suppliers are centrally engaged for reasons of economic efficiency.
Prohibition of insider trading
Insider trading is strictly prohibited. If you have access to precise, confidential, non-public information, you must not use this information to trade stocks or other financial instruments if they are likely to significantly influence the stock price of Hypoport SE or publicly traded customers, business partners, or partners. For more details, please refer to the Insider Trading Prevention Policy, which you are obliged to comply with.
Hypoport: Shaping society. Â
A safe workplace that fits life
A healthy work-life balance and the safety and health of employees are important to us. We want you to work as self-organized and responsibly as possible. This also applies, where reasonable, possible, and permissible, to the workplace and working hours. We expect you to use any flexibility and freedoms granted to you responsibly. We comply with relevant regulations in the area of occupational safety and those that ensure the protection of special groups of people, such as expectant mothers, people with disabilities.
Ecology matters
The massive impact of climate change affects us all. It is up to you and all of us to actively pay attention to the following: reducing greenhouse gas emissions, minimizing waste production, using natural resources and energy more efficiently, and thus reducing the consumption of limited resources. Where reasonable and possible, we avoid the use of fossil fuels and instead use sustainable energy sources. You are – like all of us – part of something bigger. Let’s make a difference together.
We communicate transparently
The most important rule of our exchange with each other is transparency. For the best result, it is important that you always communicate openly, honestly as well as promptly and also address conflicts or tensions in a trusting and respectful manner with your counterpart before a situation escalates.Â
How do we deal with misconduct? Â
We are all responsible for adhering to the principles of this Code of Conduct and the further Hypoport compliance regulations and Hypoport principles. In our daily interactions, we live a culture of integrity and responsibility. In this culture, management and leaders lead by example. Â
Reporting misconduct or suspected cases
To create transparency and uncover possible misconduct, it is important that misconduct or a suspected case is reported. There are different channels you can use for this, such as your supervisor, the HEB, or – if available – the compliance advisor of your Hypoport company or – insofar as relevant – the digital whistleblowing system of your Hypoport company. Hypoport SE has also set up a central whistleblower system. You can find more details in the procedural rules for the whistleblower system of Hypoport SE.
Are you unsure whether misconduct has occured? Then use this guide. It helps you analyze the situation and gives you an indication of whether you should take action and who you can contact.
How do we handle the reporting of misconduct and suspected cases?
Uncovering misconduct is essential for our credibility as an employer and business partner. Therefore, we will act as quickly as possible in the event of a report to clarify the facts. We proceed confidentially, professionally and objectively. If misconduct is present or a suspicion is confirmed, different preventive and remedial measures may be considered depending on the severity: from warnings and training measures to disciplinary measures and legal or personnel consequences. We are committed to ensuring fairness in every case and to preventing a recurrence as much as possible.
A clear no to discrimination and punishment
We believe in the value of open and honest communication. Therefore, we assure you that your report, made to the best of your knowledge and belief, will not have negative consequences for you. Discrimination and punishment contradict our core values and will result in corresponding disciplinary measures. If you have been a victim of discrimination or punishment, please report it as well.
Hypoport SE Non-Financial report / ESG reports
For information about the treatment of employees, environmental matters, combatting corruption, social responsibility and humans rights please refer the Hypoport Non-Financial Report 2024
Hypoport supplies consultancy and proven software for the structured finance market. At Hypoport, we believe we need to be invested in a more sustainable society. As such we make an effort to advance structured finance technology and consumer mortgage products while limiting our company and our clients carbon footprints.
Since residential properties are a substantial part of consumer energy usage and makes up about 26 percent of all energy usage in the European Union, we looked into the ways Hypoport could help in decreasing energy usage for households. By being a part of the market-led Energy Efficient Mortgages Initiative (2018-2020)  we used our market and product knowledge to co-create a credible, workable and pan-European energy efficient mortgage product.
Also, in 2021, Hypoport co-created the Energy Efficient Mortgage Hub – Netherlands, a knowledge hub where we aim to align European and national interest, regulation and reporting initiatives. This hub consists of representatives throughout the mortgage chain: banks, insurers, data and IT, legal forms, investors and (semi-)government organisations. Its goal is to accelerate and advance the adaptation of energy efficient housing and financing options in the Netherlands.
We work closely with a network of trusted purchasing organisations to deliver efficient and cost-effective procurement solutions for our partners and clients. By pooling resources and expertise, we help streamline processes and create lasting value across the supply chain.
Hellios
Supplier information collection and management solution that streamlines procurement due diligence with a simple, reliable process for gathering and maintaining supplier data.
EcoVadis
ESG ratings and intelligence platform supporting procurement decisions, ESG risk/compliance management, and measurable supplier sustainability improvement.
Work the way you’ve always wanted to. Start today.
Fill the form below
Reach out for personalized assistance,
inquiries, or support.
