Governance
This policy establishes phishing-resistant MFA requirements for all critical systems that store or process consumer financial data.
All systems, platforms, cloud services, and third-party integrations that store, transmit, or process financial data, including Plaid API data.
Phishing-resistant MFA required for all accounts with access to critical systems. Methods in use:
SMS-based and email-based authentication are NOT accepted for critical systems.
All devices must support and have enabled biometric authentication or hardware-based MFA. Devices without biometric capability require a hardware security key.
No exceptions for accounts with access to consumer financial data. Service accounts use scoped short-lived credentials subject to strict controls and rotation.
Reviewed annually.
Effective Date: April 1, 2026
← Back to Privacy Policy