Access Control Policy

How access to production systems and consumer financial data is granted, protected with MFA, reviewed and removed.

Effective September 27, 2026Version 1.06 sections1 min read
1

Owner and scope

Owner: LendLucid LLC / LendLucid. Security owner: Eric Zhivalyuk, Founder (support@lendlucid.com). Effective September 27, 2026.

2

Purpose

To ensure production assets and consumer financial data are accessible only to authorized persons and systems with a legitimate business need.

3

Requirements

  • LendLucid follows least-privilege and role-based access control principles.
  • Each workforce member uses an individual account where supported. Shared privileged credentials are prohibited.
  • MFA is required for privileged and administrative access to critical systems that store or process consumer financial information, including Plaid, our database and hosting provider, source control, and domain/DNS administration. Phishing-resistant MFA is used where supported.
  • Consumers must complete authenticator-app MFA before Plaid Link is surfaced; this is enforced server-side.
  • Production database access is restricted. Application access to user data is enforced through server-side authorization and row-level security that defaults to deny and prevents one consumer from accessing another’s records.
  • Plaid API secrets, Plaid access tokens, service-role keys and database administrative credentials remain server-side.
  • Non-human access uses scoped service credentials, tokens, or TLS-secured authenticated connections.
  • Access is reviewed at least quarterly and after material personnel or role changes.
  • Access is removed promptly when a person leaves or no longer requires it.
  • Privileged actions are logged and reviewed.
  • Production access is not granted solely for convenience, development or testing.
  • Contractors receive only the minimum access required, removed when the engagement ends.
4

Access review

The security owner documents quarterly reviews of privileged accounts, production access, Plaid Dashboard users, database users with elevated privileges, source-control administrators, hosting administrators and other critical systems.

5

Exceptions

Exceptions require documented approval by the security owner, a business justification, compensating controls, and an expiration or review date.

6

Contact us

LendLucid LLC, doing business as LendLucid (“LendLucid,” “we,” “us,” or “our”).

  • Privacy: support@lendlucid.com
  • Support: support@lendlucid.com
  • Security: support@lendlucid.com

Questions about this document?

We're happy to explain anything here in plain language.

LendLucid is a product and trade name operated by LendLucid LLC.

Back to top