Each organization's data is kept separate
Every application, document and transaction belongs to one organization. The database checks membership on every read and write, so one lender can't see another's files.
Security
Lenders trust LendLucid with their borrowers' bank data. Here is how we protect it.
Every application, document and transaction belongs to one organization. The database checks membership on every read and write, so one lender can't see another's files.
Owners and admins decide who joins and at what level: underwriter, broker or viewer. Each role sees and does only what it needs.
Borrowers connect accounts through Plaid. LendLucid never sees their bank credentials, and connection keys stay on our servers. They are never sent to a browser.
Uploaded statements are stored privately per organization and opened only through short-lived links for signed-in members.
Encrypted connections everywhere, optional two-step verification, single-use team invitation links that expire after seven days, and password recovery by email.
Team changes, application activity and admin actions are recorded with who did what and when.
If you believe you've found a vulnerability, email support@lendlucid.com with the details. Please don't access other customers' data or disrupt the service while testing.
Read our full security and data protection policy, or see every policy in the Legal Center.