Know before you click

Security

Version: 1.0
Effective Date: 08/15/2026
Last Reviewed: 08/15/2026
Policy Owner: Vernon Smith
Approved By: Vernon Smith

1. Purpose and Scope

This policy establishes the framework CliqSpend uses to protect the confidentiality, integrity,
and availability of its information assets, including consumer financial data, employee data, and
internal systems. It applies to all employees, contractors, and third parties who access CliqSpend systems, networks, or data.

2. Information Security Governance

Security Owner: A designated individual (e.g., CISO, Head of Security, or CTO) holds overall accountability for this policy and the information security program.

Security Contact: security@cliqspend.com (monitored group inbox for incident reports,
vendor questionnaires, and escalations)

Policy Review: This policy is reviewed at least annually, or upon significant changes to
infrastructure, regulatory requirements, or business operations.

Risk Assessments: Formal risk assessments are conducted at least annually to identify,
evaluate, and prioritize information security risks.

3. Access Control and Authentication

Principle of Least Privilege: Access to production systems, source code, and sensitive data is granted only to personnel who require it for their role.

Role-Based Access Control (RBAC): Permissions are assigned based on job function, not
individual discretion.

Multi-Factor Authentication (MFA): MFA is required for all employee access to production
environments, cloud infrastructure, and systems storing or processing consumer financial data.
MFA is also enforced for consumers before sensitive account-linking flows are surfaced.

Access Reviews: User access is reviewed quarterly, and access is revoked immediately
upon termination or role change.

  • Password Policy: Enforced minimum complexity, expiration, and prohibition of credential
    reuse across systems.

4. Network and Data Security

Encryption in Transit: All data transmitted between clients, servers, and third-party APIs(including Plaid) is encrypted using TLS 1.2 or higher.

Encryption at Rest: All consumer financial data received via the Plaid API or other sources
is encrypted at rest using AES-256 or equivalent.

Network Segmentation: Production environments are logically separated from
development/testing environments.

Firewall and Intrusion Detection: Perimeter defenses, including firewalls and intrusion
detection/prevention systems, monitor and restrict unauthorized network traffic.

Key Management: Encryption keys are managed via a dedicated key management service
(KMS) with restricted access and periodic rotation.

5. Development and Vulnerability Management –

Secure Development Lifecycle (SDLC): Security reviews and code analysis are integrated into the development process, including peer code review prior to merging into production
branches.

Vulnerability Scanning: Regular vulnerability scans are performed against
employee/contractor endpoints and production infrastructure.

Patch Management: Critical vulnerabilities are remediated according to defined SLAs (e.g.,
critical within 7 days, high within 30 days).

Penetration Testing: Third-party penetration tests are conducted at least annually, with
findings tracked to remediation.

Dependency Management: Automated tools scan for vulnerable third-party libraries and
dependencies.

6. Incident Response

Incident Response Plan: A documented incident response plan defines roles, escalation

paths, and communication procedures for security incidents.

Detection and Monitoring: Logging and monitoring tools are in place across production
systems to detect anomalous activity.

  • Breach Notification: In the event of a data breach involving consumer data, affected parties
    and relevant regulators are notified in accordance with applicable law (e.g., state breach
    notification laws, GDPR where applicable). –
  • Post-Incident Review: All significant incidents undergo a root cause analysis and
    remediation plan.

7. Privacy and Consumer Data Rights

Privacy Policy: CliqSpend maintains a publicly available privacy policy describing data collection, use, and sharing practices. Privacy Policy

Consumer Consent: Explicit consumer consent is obtained prior to collecting, processing,
or storing personal or financial data. –

Data Minimization: Only data necessary for the application’s functionality is collected and
retained.

Data Retention and Deletion: A documented data retention schedule governs how long
consumer data is stored, with secure deletion processes upon request or expiration of the
retention period. This policy is reviewed periodically for compliance with applicable laws (e.g.,
CCPA, GDPR, GLBA).

Consumer Rights: Consumers may request access to, correction of, or deletion of their
personal data, consistent with applicable privacy regulations.

8. Third-Party and Vendor Risk Management

Vendor Due Diligence: Third-party vendors with access to consumer data undergo a security review prior to onboarding.

Data Processing Agreements: Contracts with vendors handling consumer data include data
protection obligations.

Ongoing Monitoring: Vendor security posture is reassessed periodically (e.g., annually or
upon contract renewal).

9. Employee Security Awareness

Security Training: All employees complete security awareness training upon onboarding and annually thereafter.

Phishing Simulations: Periodic simulated phishing exercises are conducted to reinforce awareness.

Acceptable Use Policy: Employees agree to an acceptable use policy governing
appropriate use of company systems and data.

10. Physical Security

Data Center Security: Production infrastructure is hosted with cloud providers AWS that maintain SOC 2 Type II or equivalent certifications.

Office Access Controls: Physical access to company offices is restricted via badge access,
with visitor logs maintained.

11. Policy Enforcement

Violations of this policy may result in disciplinary action, up to and including termination of
employment or contract, and may be reported to relevant authorities where required by law.