Legal

Information Security Policy

The foundation of MonthlyIQ's security program: governance, data protection, access, development, monitoring and third parties.

Effective September 27, 2026Last updated September 27, 2026Version 1.0

1. Owner and scope

Owner: Capalty LLC / MonthlyIQ. Security owner: Eric Zhivalyuk, Founder (security@monthlyiq.com). Effective September 27, 2026.

2. Purpose

MonthlyIQ maintains an information security program designed to protect the confidentiality, integrity and availability of consumer information, including financial data obtained through Plaid.

3. Scope

This policy applies to MonthlyIQ personnel, contractors, systems, applications, databases, cloud services, source code, production infrastructure, credentials, and third-party services that access or process consumer information.

4. Governance

Management is responsible for the security program. A designated security owner maintains policies, coordinates risk review, manages incidents and ensures remediation. Policies are reviewed at least annually and after material security incidents or architectural changes.

5. Data protection

MonthlyIQ uses modern industry-standard cryptography for consumer information in transit and at rest. Production traffic uses HTTPS/TLS 1.2 or better. Plaid client IDs, secrets, access tokens, service-role credentials and other privileged credentials are stored only in approved server-side secret storage and are never exposed in client-side code, browser storage, URLs, analytics or logs.

6. Access control

Access to production systems and consumer financial data is restricted to authorized personnel with a legitimate business need, under least-privilege and role-based principles. Shared production credentials are prohibited where individual accounts are available. Privileged access requires MFA, and consumers must complete MFA before Plaid Link is surfaced. Access is reviewed periodically and removed promptly when no longer required. See the Access Control Policy.

7. Application and database security

Authorization is enforced server-side. Row-level security is enabled on every table containing user or financial data, with default-deny policies and user/household isolation. Service-role credentials are never exposed to clients. Sensitive administrative actions are logged.

8. Secure development

Production changes are reviewed and tested before release. Dependencies and production assets are monitored for known vulnerabilities, with critical and high-risk findings prioritized. Secret scanning and dependency monitoring are used where supported. See the Vulnerability and Patch Management Policy.

9. Logging and monitoring

MonthlyIQ maintains security-relevant logging for authentication, privileged access, account linking and unlinking, consent, configuration changes, deletion requests and material authorization failures. Logs must not contain passwords, bank credentials, Plaid secrets, access tokens or unnecessary financial data.

10. Incident response

Suspected unauthorized access, credential compromise or consumer-data exposure is escalated promptly under the Incident Response Plan. Credentials are revocable and rotatable, and MonthlyIQ makes legally and contractually required notifications.

11. Data minimization and retention

MonthlyIQ collects and retains only data reasonably necessary to provide the Service, meet legal obligations, protect security and resolve disputes, and deletes or de-identifies it when no longer needed under the Data Retention and Deletion Policy.

12. Third parties

Service providers that process sensitive information are evaluated for appropriate security and privacy safeguards, and access and data sharing are limited to the services required. See our Vendors & Subprocessors page.

13. Training and compliance

Personnel with access to sensitive systems must follow these requirements and promptly report suspected security events. Violations may result in access removal or other corrective action.

14. Contact us

Capalty LLC, doing business as MonthlyIQ (“MonthlyIQ,” “we,” “us,” or “our”).

MonthlyIQ is a product and trade name operated by Capalty LLC, a Florida limited liability company.