Version: 1.0
Effective Date: 08/15/2026
Last Reviewed: 08/15/2026
Policy Owner: Vernon Smith
Approved By: Vernon Smith
1. Purpose and Scope
This policy establishes the framework CliqSpend uses to protect the confidentiality, integrity,
and availability of its information assets, including consumer financial data, employee data, and
internal systems. It applies to all employees, contractors, and third parties who access CliqSpend systems, networks, or data.
2. Information Security Governance
Security Owner: A designated individual (e.g., CISO, Head of Security, or CTO) holds overall accountability for this policy and the information security program.
Security Contact: security@cliqspend.com (monitored group inbox for incident reports,
vendor questionnaires, and escalations)
Policy Review: This policy is reviewed at least annually, or upon significant changes to
infrastructure, regulatory requirements, or business operations.
Risk Assessments: Formal risk assessments are conducted at least annually to identify,
evaluate, and prioritize information security risks.
3. Access Control and Authentication
Principle of Least Privilege: Access to production systems, source code, and sensitive data is granted only to personnel who require it for their role.
Role-Based Access Control (RBAC): Permissions are assigned based on job function, not
individual discretion.
Multi-Factor Authentication (MFA): MFA is required for all employee access to production
environments, cloud infrastructure, and systems storing or processing consumer financial data.
MFA is also enforced for consumers before sensitive account-linking flows are surfaced.
Access Reviews: User access is reviewed quarterly, and access is revoked immediately
upon termination or role change.
- Password Policy: Enforced minimum complexity, expiration, and prohibition of credential
reuse across systems.
4. Network and Data Security
Encryption in Transit: All data transmitted between clients, servers, and third-party APIs(including Plaid) is encrypted using TLS 1.2 or higher.
Encryption at Rest: All consumer financial data received via the Plaid API or other sources
is encrypted at rest using AES-256 or equivalent.
Network Segmentation: Production environments are logically separated from
development/testing environments.
Firewall and Intrusion Detection: Perimeter defenses, including firewalls and intrusion
detection/prevention systems, monitor and restrict unauthorized network traffic.
Key Management: Encryption keys are managed via a dedicated key management service
(KMS) with restricted access and periodic rotation.
5. Development and Vulnerability Management –
Secure Development Lifecycle (SDLC): Security reviews and code analysis are integrated into the development process, including peer code review prior to merging into production
branches.
Vulnerability Scanning: Regular vulnerability scans are performed against
employee/contractor endpoints and production infrastructure.
Patch Management: Critical vulnerabilities are remediated according to defined SLAs (e.g.,
critical within 7 days, high within 30 days).
Penetration Testing: Third-party penetration tests are conducted at least annually, with
findings tracked to remediation.
Dependency Management: Automated tools scan for vulnerable third-party libraries and
dependencies.
6. Incident Response
Incident Response Plan: A documented incident response plan defines roles, escalation
paths, and communication procedures for security incidents.
Detection and Monitoring: Logging and monitoring tools are in place across production
systems to detect anomalous activity.
- Breach Notification: In the event of a data breach involving consumer data, affected parties
and relevant regulators are notified in accordance with applicable law (e.g., state breach
notification laws, GDPR where applicable). – - Post-Incident Review: All significant incidents undergo a root cause analysis and
remediation plan.
7. Privacy and Consumer Data Rights
Privacy Policy: CliqSpend maintains a publicly available privacy policy describing data collection, use, and sharing practices. Privacy Policy
Consumer Consent: Explicit consumer consent is obtained prior to collecting, processing,
or storing personal or financial data. –
Data Minimization: Only data necessary for the application’s functionality is collected and
retained.
Data Retention and Deletion: A documented data retention schedule governs how long
consumer data is stored, with secure deletion processes upon request or expiration of the
retention period. This policy is reviewed periodically for compliance with applicable laws (e.g.,
CCPA, GDPR, GLBA).
Consumer Rights: Consumers may request access to, correction of, or deletion of their
personal data, consistent with applicable privacy regulations.
8. Third-Party and Vendor Risk Management
Vendor Due Diligence: Third-party vendors with access to consumer data undergo a security review prior to onboarding.
Data Processing Agreements: Contracts with vendors handling consumer data include data
protection obligations.
Ongoing Monitoring: Vendor security posture is reassessed periodically (e.g., annually or
upon contract renewal).
9. Employee Security Awareness
Security Training: All employees complete security awareness training upon onboarding and annually thereafter.
Phishing Simulations: Periodic simulated phishing exercises are conducted to reinforce awareness.
Acceptable Use Policy: Employees agree to an acceptable use policy governing
appropriate use of company systems and data.
10. Physical Security
Data Center Security: Production infrastructure is hosted with cloud providers AWS that maintain SOC 2 Type II or equivalent certifications.
Office Access Controls: Physical access to company offices is restricted via badge access,
with visitor logs maintained.
11. Policy Enforcement
Violations of this policy may result in disciplinary action, up to and including termination of
employment or contract, and may be reported to relevant authorities where required by law.