Information Security Policy
Last revised: September 25, 2026
BorrowBetter ("BorrowBetter," "we," "us," or "our") maintains an information security program to protect the non-public personal information ("NPI") of consumers who use our platform.
This page summarizes our security requirements and platform design for protecting NPI from collection through storage, transmission, and disposal.
1. Scope
This policy applies to all NPI collected, processed, stored, or transmitted by BorrowBetter, including:
- Personally identifiable information: Name, email address, phone number, mailing address, date of birth, and Social Security number
- Financial information: Income, employment details, banking information, loan preferences, and debt amounts
- Credit information: Credit scores, credit reports, and credit history obtained with consumer consent
- Technical data: IP addresses, device information, session identifiers, and site analytics
2. Program Overview
Our information security program is designed to protect the confidentiality, integrity, and availability of consumer NPI; guard against anticipated threats and unauthorized access; and comply with applicable federal and state law, including the GLBA Safeguards Rule and the Fair Credit Reporting Act.
3. Administrative Safeguards
3.1 Security Leadership
The CEO provides senior-officer oversight of BorrowBetter’s security and compliance program. The CTO leads technical security and platform operations. Security responsibilities include risk assessment, incident coordination, policy maintenance and follow-through on identified issues.
3.2 Personnel Security
- Background screening: All founders, employees and individual contractors are required to complete background checks before receiving company system or information access, including criminal-history screening where lawful. Founder status does not create an exemption.
- Security training: Employees and contractors with company system or information access are required to complete relevant security and privacy training during onboarding and at least annually.
- Confidentiality: Employees and contractors must be subject to confidentiality obligations before access to protected information.
- Least privilege access: Access to systems and data is granted based on role and limited to what the role requires
3.3 Risk Assessment
We assess risks to consumer information at least annually and on material change to our systems, vendors, or operations, including evaluation of internal and external threats, system vulnerabilities, and the effectiveness of existing safeguards.
4. Technical Safeguards
4.1 Encryption
- Data in transit: All data transmitted between users and our platform is encrypted using TLS 1.2 or higher
- Data at rest: Sensitive data, including Social Security numbers, is encrypted using AES-256
- Database encryption: Our managed database is encrypted at rest
4.2 Access Controls
- Identity and authentication: Okta is our workforce single sign-on (SSO) provider. Access to company systems follows our access-control requirements, including multi-factor authentication for privileged and production access. Consumer authentication is separate from workforce SSO.
- Least privilege: Access is limited to authorized business needs. Our policy requires access reviews at least annually and access changes when roles or engagements change.
- Production access: Access to production systems and databases requires authorization, appropriate access restrictions and audit logging. Emergency access follows documented approval and review procedures.
- Session management: User sessions are secured with cryptographically strong session tokens
4.3 Monitoring and Detection
- Monitoring and response: Service logs and security-monitoring capabilities support detection and investigation of suspicious activity. Response follows our incident procedures and may include containment or access restrictions according to the event.
- Logging requirements: Relevant production access, administrative changes and security events must be logged and protected against unauthorized access or alteration. Coverage, retention and alert ownership are maintained as part of operations security.
4.4 Secure Development
- Input validation: User inputs are validated and sanitized to prevent injection attacks
- Environment separation: Development, staging, and production environments are segregated
- Change control: All repositories in the BorrowBetter GitHub organization inherit default-branch rulesets. Production changes require a pull request and passing Aikido security scanning and the repository’s ci checks; no person or bot may bypass either check. Authorized review and self-merge arrangements are governed by our change policy. CI/CD deploys from main after merge, including application, infrastructure, data and ML workloads.
- Vulnerability scanning: Our code and third-party dependencies are scanned for vulnerabilities on an ongoing basis
- Secrets management: Credentials, API keys and encryption keys must be held in approved secure configuration or secrets-management services, with restricted access, rather than committed to source code.
5. Infrastructure Security
BorrowBetter uses managed cloud services with distinct responsibilities:
- Vercel hosts our consumer-facing websites and applications.
- Amazon Web Services (AWS) runs our backend services and supporting infrastructure.
- Neon provides our production PostgreSQL databases.
- Snowflake provides our data warehouse.
Security is a shared responsibility. Providers operate their underlying facilities and managed services; BorrowBetter is responsible for its applications, data handling, access and service configuration. Provider assurance evidence must be reviewed for the relevant service and period, and does not itself establish BorrowBetter’s compliance.
Our infrastructure requirements cover encryption, environment separation, access restrictions, logging, backups and recovery appropriate to each service. Recovery procedures must be exercised and findings tracked.
6. Third-Party Vendor Management
- Service providers: Our requirements include risk-based due diligence and suitable confidentiality, security and privacy terms for providers handling protected information. High-risk providers require at least annual review and reassessment after material changes or relevant incidents.
- Recipient partners: Sharing with lenders and other recipient partners requires an authorized purpose, applicable consumer permissions, written agreements and appropriate safeguards. Requirements reflect whether the recipient acts on our behalf or for its own authorized purposes.
- Secure transmission: Data is transmitted to partners through encrypted connections
- Limited data sharing: Only information necessary for the specific business purpose is shared with each partner
7. Incident Response
BorrowBetter maintains a documented incident response plan covering detection, containment, investigation, remediation, and post-incident review. In the event of a breach affecting consumer NPI, we will notify affected individuals and regulatory authorities as required by applicable law.
8. Data Retention and Disposal
Consumer information is retained only as long as necessary to fulfill business purposes and legal obligations:
- Lead data is retained for the period necessary to complete partner matching and fulfill regulatory requirements
- Credit-related data is retained in accordance with Fair Credit Reporting Act requirements
- Retention requirements call for secure deletion or anonymization when information is no longer needed, subject to documented legal holds and other applicable retention obligations.
- Verified consumer deletion requests are handled under applicable privacy requirements, including lawful exceptions, relevant recipients and backup handling.
9. Consumer Rights
Consumers may exercise their rights regarding their personal information by contacting us at:
Email: privacy@borrowbetter.com
We respond to verified consumer requests in accordance with applicable state and federal privacy laws.
10. Policy Review and Updates
This page is reviewed at least annually and updated as needed to reflect changes in our operations, technology, threats, or applicable law. Material changes will be reflected in the "Last revised" date above.
11. Contact Information
For questions about this policy or BorrowBetter's security practices, please contact:
BorrowBetter Security
Email: security@borrowbetter.com