Security

Bank data handled with care, at every step.

Lenders trust LendLucid with their borrowers' bank data. Here is how we protect it.

Each organization's data is kept separate

Every application, document and transaction belongs to one organization. The database checks membership on every read and write, so one lender can't see another's files.

Access by role

Owners and admins decide who joins and at what level: underwriter, broker or viewer. Each role sees and does only what it needs.

Bank connections without bank passwords

Borrowers connect accounts through Plaid. LendLucid never sees their bank credentials, and connection keys stay on our servers. They are never sent to a browser.

Private document storage

Uploaded statements are stored privately per organization and opened only through short-lived links for signed-in members.

Sign-in protection

Encrypted connections everywhere, optional two-step verification, single-use team invitation links that expire after seven days, and password recovery by email.

Audit history

Team changes, application activity and admin actions are recorded with who did what and when.

Report a security concern

If you believe you've found a vulnerability, email support@lendlucid.com with the details. Please don't access other customers' data or disrupt the service while testing.

Policies

Read our full security and data protection policy, or see every policy in the Legal Center.