Legal

Access Control Policy

How access to production systems and consumer financial data is granted, protected with MFA, reviewed and removed.

Effective September 27, 2026Last updated September 27, 2026Version 1.0

1. Owner and scope

Owner: Capalty LLC / MonthlyIQ. Security owner: Eric Zhivalyuk, Founder (security@monthlyiq.com). Effective September 27, 2026.

2. Purpose

To ensure production assets and consumer financial data are accessible only to authorized persons and systems with a legitimate business need.

3. Requirements

  • MonthlyIQ follows least-privilege and role-based access control principles.
  • Each workforce member uses an individual account where supported. Shared privileged credentials are prohibited.
  • MFA is required for privileged and administrative access to critical systems that store or process consumer financial information, including Plaid, our database and hosting provider, source control, and domain/DNS administration. Phishing-resistant MFA is used where supported.
  • Consumers must complete authenticator-app MFA before Plaid Link is surfaced; this is enforced server-side.
  • Production database access is restricted. Application access to user data is enforced through server-side authorization and row-level security that defaults to deny and prevents one consumer from accessing another’s records.
  • Plaid API secrets, Plaid access tokens, service-role keys and database administrative credentials remain server-side.
  • Non-human access uses scoped service credentials, tokens, or TLS-secured authenticated connections.
  • Access is reviewed at least quarterly and after material personnel or role changes.
  • Access is removed promptly when a person leaves or no longer requires it.
  • Privileged actions are logged and reviewed.
  • Production access is not granted solely for convenience, development or testing.
  • Contractors receive only the minimum access required, removed when the engagement ends.

4. Access review

The security owner documents quarterly reviews of privileged accounts, production access, Plaid Dashboard users, database users with elevated privileges, source-control administrators, hosting administrators and other critical systems.

5. Exceptions

Exceptions require documented approval by the security owner, a business justification, compensating controls, and an expiration or review date.

6. Contact us

Capalty LLC, doing business as MonthlyIQ (“MonthlyIQ,” “we,” “us,” or “our”).

MonthlyIQ is a product and trade name operated by Capalty LLC, a Florida limited liability company.