BorrowBetter

AboutFAQContact
  1. Legal
  2. Information Security Policy

Information Security Policy

Last revised: September 25, 2026

BorrowBetter ("BorrowBetter," "we," "us," or "our") maintains an information security program to protect the non-public personal information ("NPI") of consumers who use our platform.

This page summarizes our security requirements and platform design for protecting NPI from collection through storage, transmission, and disposal.

1. Scope

This policy applies to all NPI collected, processed, stored, or transmitted by BorrowBetter, including:

  • Personally identifiable information: Name, email address, phone number, mailing address, date of birth, and Social Security number
  • Financial information: Income, employment details, banking information, loan preferences, and debt amounts
  • Credit information: Credit scores, credit reports, and credit history obtained with consumer consent
  • Technical data: IP addresses, device information, session identifiers, and site analytics

2. Program Overview

Our information security program is designed to protect the confidentiality, integrity, and availability of consumer NPI; guard against anticipated threats and unauthorized access; and comply with applicable federal and state law, including the GLBA Safeguards Rule and the Fair Credit Reporting Act.

3. Administrative Safeguards

3.1 Security Leadership

The CEO provides senior-officer oversight of BorrowBetter’s security and compliance program. The CTO leads technical security and platform operations. Security responsibilities include risk assessment, incident coordination, policy maintenance and follow-through on identified issues.

3.2 Personnel Security

  • Background screening: All founders, employees and individual contractors are required to complete background checks before receiving company system or information access, including criminal-history screening where lawful. Founder status does not create an exemption.
  • Security training: Employees and contractors with company system or information access are required to complete relevant security and privacy training during onboarding and at least annually.
  • Confidentiality: Employees and contractors must be subject to confidentiality obligations before access to protected information.
  • Least privilege access: Access to systems and data is granted based on role and limited to what the role requires

3.3 Risk Assessment

We assess risks to consumer information at least annually and on material change to our systems, vendors, or operations, including evaluation of internal and external threats, system vulnerabilities, and the effectiveness of existing safeguards.

4. Technical Safeguards

4.1 Encryption

  • Data in transit: All data transmitted between users and our platform is encrypted using TLS 1.2 or higher
  • Data at rest: Sensitive data, including Social Security numbers, is encrypted using AES-256
  • Database encryption: Our managed database is encrypted at rest

4.2 Access Controls

  • Identity and authentication: Okta is our workforce single sign-on (SSO) provider. Access to company systems follows our access-control requirements, including multi-factor authentication for privileged and production access. Consumer authentication is separate from workforce SSO.
  • Least privilege: Access is limited to authorized business needs. Our policy requires access reviews at least annually and access changes when roles or engagements change.
  • Production access: Access to production systems and databases requires authorization, appropriate access restrictions and audit logging. Emergency access follows documented approval and review procedures.
  • Session management: User sessions are secured with cryptographically strong session tokens

4.3 Monitoring and Detection

  • Monitoring and response: Service logs and security-monitoring capabilities support detection and investigation of suspicious activity. Response follows our incident procedures and may include containment or access restrictions according to the event.
  • Logging requirements: Relevant production access, administrative changes and security events must be logged and protected against unauthorized access or alteration. Coverage, retention and alert ownership are maintained as part of operations security.

4.4 Secure Development

  • Input validation: User inputs are validated and sanitized to prevent injection attacks
  • Environment separation: Development, staging, and production environments are segregated
  • Change control: All repositories in the BorrowBetter GitHub organization inherit default-branch rulesets. Production changes require a pull request and passing Aikido security scanning and the repository’s ci checks; no person or bot may bypass either check. Authorized review and self-merge arrangements are governed by our change policy. CI/CD deploys from main after merge, including application, infrastructure, data and ML workloads.
  • Vulnerability scanning: Our code and third-party dependencies are scanned for vulnerabilities on an ongoing basis
  • Secrets management: Credentials, API keys and encryption keys must be held in approved secure configuration or secrets-management services, with restricted access, rather than committed to source code.

5. Infrastructure Security

BorrowBetter uses managed cloud services with distinct responsibilities:

  • Vercel hosts our consumer-facing websites and applications.
  • Amazon Web Services (AWS) runs our backend services and supporting infrastructure.
  • Neon provides our production PostgreSQL databases.
  • Snowflake provides our data warehouse.

Security is a shared responsibility. Providers operate their underlying facilities and managed services; BorrowBetter is responsible for its applications, data handling, access and service configuration. Provider assurance evidence must be reviewed for the relevant service and period, and does not itself establish BorrowBetter’s compliance.

Our infrastructure requirements cover encryption, environment separation, access restrictions, logging, backups and recovery appropriate to each service. Recovery procedures must be exercised and findings tracked.

6. Third-Party Vendor Management

  • Service providers: Our requirements include risk-based due diligence and suitable confidentiality, security and privacy terms for providers handling protected information. High-risk providers require at least annual review and reassessment after material changes or relevant incidents.
  • Recipient partners: Sharing with lenders and other recipient partners requires an authorized purpose, applicable consumer permissions, written agreements and appropriate safeguards. Requirements reflect whether the recipient acts on our behalf or for its own authorized purposes.
  • Secure transmission: Data is transmitted to partners through encrypted connections
  • Limited data sharing: Only information necessary for the specific business purpose is shared with each partner

7. Incident Response

BorrowBetter maintains a documented incident response plan covering detection, containment, investigation, remediation, and post-incident review. In the event of a breach affecting consumer NPI, we will notify affected individuals and regulatory authorities as required by applicable law.

8. Data Retention and Disposal

Consumer information is retained only as long as necessary to fulfill business purposes and legal obligations:

  • Lead data is retained for the period necessary to complete partner matching and fulfill regulatory requirements
  • Credit-related data is retained in accordance with Fair Credit Reporting Act requirements
  • Retention requirements call for secure deletion or anonymization when information is no longer needed, subject to documented legal holds and other applicable retention obligations.
  • Verified consumer deletion requests are handled under applicable privacy requirements, including lawful exceptions, relevant recipients and backup handling.

9. Consumer Rights

Consumers may exercise their rights regarding their personal information by contacting us at:

Email: privacy@borrowbetter.com

We respond to verified consumer requests in accordance with applicable state and federal privacy laws.

10. Policy Review and Updates

This page is reviewed at least annually and updated as needed to reflect changes in our operations, technology, threats, or applicable law. Material changes will be reflected in the "Last revised" date above.

11. Contact Information

For questions about this policy or BorrowBetter's security practices, please contact:

BorrowBetter Security

Email: security@borrowbetter.com

We are not a lender. The operator of this website is not a lender, does not make offers for loans, and does not make credit decisions. Rather, we seek to pair consumers with approved lenders and lending partners. Please note, the lender or lending partner you are connected with may not offer you the most favorable loan terms for your financial circumstances. This website is not a representative, agent, or broker of any lender or lending partner. We have no authority over and disclaim responsibility for the actions and omissions of lenders and lending partners. We do not guarantee that you will receive a loan offer from a lender or lending partner, or approval for a loan. We do not control the amount of fees you may be charged upon nonpayment, late payment, or partial payment. Please contact your lender or lending partner directly with questions regarding your loan.

About personal loans. Personal loans are online loans which generally range from $1,000 to $40,000. These loans are not intended to be solutions to long-term financial issues. Consumers who have credit problems or who are facing debt should seek professional financial advice, learn of the risks involved with taking out loans, and consider loan alternatives that may be more suitable to your financial circumstances. We strongly encourage you to read and understand the terms of any loan offered to you by a lender or lending partner. If you miss a payment or make a late payment, additional fees may apply and your credit score can be negatively affected. Reject any loan offer that you cannot afford to repay or that offers terms that you cannot agree to.

© 2026 BorrowBetter. All rights reserved.

About

FAQ

Contact

Legal