1. Owner and scope
Owner: Capalty LLC / MonthlyIQ. Security owner: Eric Zhivalyuk, Founder (security@monthlyiq.com). Effective September 27, 2026.
2. Purpose
MonthlyIQ maintains an information security program designed to protect the confidentiality, integrity and availability of consumer information, including financial data obtained through Plaid.
3. Scope
This policy applies to MonthlyIQ personnel, contractors, systems, applications, databases, cloud services, source code, production infrastructure, credentials, and third-party services that access or process consumer information.
4. Governance
Management is responsible for the security program. A designated security owner maintains policies, coordinates risk review, manages incidents and ensures remediation. Policies are reviewed at least annually and after material security incidents or architectural changes.
5. Data protection
MonthlyIQ uses modern industry-standard cryptography for consumer information in transit and at rest. Production traffic uses HTTPS/TLS 1.2 or better. Plaid client IDs, secrets, access tokens, service-role credentials and other privileged credentials are stored only in approved server-side secret storage and are never exposed in client-side code, browser storage, URLs, analytics or logs.
6. Access control
Access to production systems and consumer financial data is restricted to authorized personnel with a legitimate business need, under least-privilege and role-based principles. Shared production credentials are prohibited where individual accounts are available. Privileged access requires MFA, and consumers must complete MFA before Plaid Link is surfaced. Access is reviewed periodically and removed promptly when no longer required. See the Access Control Policy.
7. Application and database security
Authorization is enforced server-side. Row-level security is enabled on every table containing user or financial data, with default-deny policies and user/household isolation. Service-role credentials are never exposed to clients. Sensitive administrative actions are logged.
8. Secure development
Production changes are reviewed and tested before release. Dependencies and production assets are monitored for known vulnerabilities, with critical and high-risk findings prioritized. Secret scanning and dependency monitoring are used where supported. See the Vulnerability and Patch Management Policy.
9. Logging and monitoring
MonthlyIQ maintains security-relevant logging for authentication, privileged access, account linking and unlinking, consent, configuration changes, deletion requests and material authorization failures. Logs must not contain passwords, bank credentials, Plaid secrets, access tokens or unnecessary financial data.
10. Incident response
Suspected unauthorized access, credential compromise or consumer-data exposure is escalated promptly under the Incident Response Plan. Credentials are revocable and rotatable, and MonthlyIQ makes legally and contractually required notifications.
11. Data minimization and retention
MonthlyIQ collects and retains only data reasonably necessary to provide the Service, meet legal obligations, protect security and resolve disputes, and deletes or de-identifies it when no longer needed under the Data Retention and Deletion Policy.
12. Third parties
Service providers that process sensitive information are evaluated for appropriate security and privacy safeguards, and access and data sharing are limited to the services required. See our Vendors & Subprocessors page.
13. Training and compliance
Personnel with access to sensitive systems must follow these requirements and promptly report suspected security events. Violations may result in access removal or other corrective action.
14. Contact us
Capalty LLC, doing business as MonthlyIQ (“MonthlyIQ,” “we,” “us,” or “our”).
- Privacy: privacy@monthlyiq.com
- Support: support@monthlyiq.com
- Security: security@monthlyiq.com
- Mail: 500 S. Australian Ave., Ste 600 #1072, West Palm Beach, FL 33480
MonthlyIQ is a product and trade name operated by Capalty LLC, a Florida limited liability company.
