Owner and scope
Owner: LendLucid LLC / LendLucid. Security owner: Eric Zhivalyuk, Founder (support@lendlucid.com). Effective September 27, 2026.
Purpose
LendLucid identifies, evaluates and remediates security vulnerabilities affecting production assets, application dependencies, and workforce endpoints that can access sensitive systems.
Program
- Dependency and source-code vulnerability alerts are enabled where supported.
- Secret scanning is enabled for source repositories where supported.
- Automated database security scanning checks access policies and configuration.
- Internet-facing production assets are periodically scanned for known vulnerabilities and insecure configuration.
- Workforce computers with production access use current supported operating systems, automatic security updates, device lock and endpoint protection.
- End-of-life software is upgraded, removed, isolated or formally risk-accepted.
- Findings are triaged by severity, exploitability, exposure and data sensitivity.
Remediation targets
- Critical: as soon as practicable, target within 7 calendar days.
- High: within 30 calendar days.
- Medium: within 90 calendar days.
- Low: through normal maintenance based on risk.
- Missed targets are documented with reason, interim mitigation, owner and revised date.
Secure releases
Material production changes are reviewed and tested before deployment. Production errors must not expose secrets, credentials, access tokens, database details or unnecessary consumer financial information.
Review
Reviewed at least annually and after material incidents or architectural changes.
Contact us
LendLucid LLC, doing business as LendLucid (“LendLucid,” “we,” “us,” or “our”).
- Privacy: support@lendlucid.com
- Support: support@lendlucid.com
- Security: support@lendlucid.com
Questions about this document?
We're happy to explain anything here in plain language.
LendLucid is a product and trade name operated by LendLucid LLC.
Back to top