Our approach
Your financial data is not an advertising product. LendLucid is designed so that we see only what we need to provide the Service, and every record is isolated to your household. Our program is documented in written policies that are reviewed at least annually and are listed below.
Security ownership
Information security is owned by Eric Zhivalyuk, Founder and Authorized Representative of LendLucid LLC. Security matters can be sent to our monitored group address support@lendlucid.com.
Secure bank connections
Accounts connect through Plaid. You enter your bank credentials with Plaid or your institution — LendLucid never receives or stores your banking username or password. LendLucid receives read-only access and cannot move money.
Multi-factor authentication for consumers
Before Plaid Link is shown, every user must complete two-step verification using a time-based one-time code (TOTP) from an authenticator app such as Google Authenticator, Microsoft Authenticator, 1Password or Authy. First-time users enroll by scanning a QR code; returning users enter a fresh 6-digit code. This requirement is enforced on our servers: a bank connection cannot be started from a session that has not passed the second factor. Users can view or remove their authenticator in Settings → Security & sign-in.
Multi-factor authentication for our team
Multi-factor authentication is required for all administrative access to critical systems that store or process consumer financial data, including the Plaid Dashboard, our cloud database and hosting administration, source control, and domain/DNS administration. Phishing-resistant methods (such as passkeys, platform biometrics or hardware security keys) are used where the provider supports them. Shared privileged credentials are prohibited.
Encryption in transit and at rest
All traffic between your browser and LendLucid, and between LendLucid and Plaid, is encrypted with TLS 1.2 or higher. Consumer data retrieved from the Plaid API is encrypted at rest by our database provider (AES-256). Plaid access tokens receive an additional layer of application-level AES-256-GCM encryption before storage, are decrypted only on our servers, and are never sent to your browser.
Access controls
- Least-privilege, role-based access control, documented in our Access Control Policy.
- Database row-level security defaults to deny and isolates each household’s records from every other household.
- Application roles are stored separately from household membership and verified server-side.
- Plaid secrets, access tokens and service credentials stay server-side; non-human access uses scoped tokens over TLS.
- Privileged access is reviewed at least quarterly and removed promptly when no longer needed.
- Administrative changes are recorded in an audit log.
Account security
Sign-in options include email and password (minimum 12 characters), secure email links, and Google sign-in, with authenticator-app two-step verification for bank connections. Keep your credentials private and contact us immediately if you suspect unauthorized access.
Vulnerability and patch management
- Automated dependency, code and database-configuration security scanning, including secret scanning where supported.
- Periodic scanning of internet-facing production assets.
- Workforce devices with production access use supported operating systems, automatic security updates, device lock and endpoint protection.
- Remediation targets: critical within 7 days, high within 30 days, medium within 90 days, low through normal maintenance.
- Production changes are reviewed and tested before release; errors never expose secrets or tokens.
Logging and analytics
We avoid logging sensitive financial details. We do not use session-replay tools on financial screens and do not send financial data to advertising or analytics networks.
Retention and deletion
We keep data only as long as needed to provide the Service. Disconnecting an institution or deleting your account revokes the Plaid connection and stops new collection. Deleted data may remain in encrypted backups until they are overwritten. See our Data Retention and Deletion Policy.
You stay in control
- Disconnect any institution from Accounts at any time.
- Delete your account and household data from Settings.
- Submit privacy requests through our Privacy Request form.
Security incidents
We maintain a written Incident Response Plan covering identification, containment, investigation, recovery, notification and post-incident review. If an incident affects your personal information we will notify affected users, regulators and partners (including Plaid) as required by law and our agreements.
Our security policies
- Information Security Policy — https://lendlucid.com/policies/information-security
- Access Control Policy — https://lendlucid.com/policies/access-control
- Vulnerability and Patch Management Policy — https://lendlucid.com/policies/vulnerability-management
- Incident Response Plan — https://lendlucid.com/policies/incident-response
- Data Retention and Deletion Policy — https://lendlucid.com/policies/data-retention
- Consumer Data Request Procedure — https://lendlucid.com/policies/consumer-requests
- Vendor and Subprocessor Register — https://lendlucid.com/subprocessors
Responsible disclosure
If you believe you have found a security vulnerability, please email support@lendlucid.com with details. Please do not access or modify other users’ data, disrupt the Service, or publicly disclose the issue before we have had a reasonable opportunity to fix it. We will not pursue legal action against good-faith research that follows these guidelines.
Limitations
No method of transmission or storage is completely secure. We do not claim any third-party security certification at this time.
Contact us
LendLucid LLC, doing business as LendLucid (“LendLucid,” “we,” “us,” or “our”).
- Privacy: support@lendlucid.com
- Support: support@lendlucid.com
- Security: support@lendlucid.com
Questions about this document?
We're happy to explain anything here in plain language.
LendLucid is a product and trade name operated by LendLucid LLC.
Back to top