Skip to main content
ClearValue Lending

Security at ClearValue Lending

Effective May 6, 2026. This statement describes the safeguards we maintain to protect personal and business information. It is informational and does not create any contractual obligation beyond what is set forth in our Terms of Use and Privacy Policy.

Our Approach

We take the security of your information seriously. Because we collect financial and identifying information in connection with applications for commercial financing, we maintain administrative, technical, and physical safeguards designed to protect that information against unauthorized access, alteration, disclosure, or destruction. Our written information security program is designed to meet the requirements of applicable law, including the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 C.F.R. Part 314), and to align with widely-adopted information-security frameworks.

Information Security Program and Governance

  • We maintain a written information security program proportionate to the size and complexity of our operations and the sensitivity of the information we handle.
  • We have designated a Qualified Individual to oversee, implement, and enforce our information security program, consistent with the FTC Safeguards Rule. The Qualified Individual reports periodically (and at least annually) to senior leadership on the status of the program, risks identified, and remediation activities.
  • We perform written risk assessments to identify reasonably foreseeable internal and external threats and to evaluate the sufficiency of our safeguards.
  • We provide security awareness training to personnel and require role-appropriate training for personnel with elevated access.

Encryption in Transit and at Rest

  • Connections to our public website and application portal are protected with industry-standard transport-layer encryption (TLS 1.2 or higher) with modern cipher suites.
  • Sensitive personal information stored in our managed database infrastructure is encrypted at rest using strong, widely-adopted symmetric encryption algorithms (such as AES-256) provided by our cloud infrastructure providers, or — where encryption is infeasible for a particular control point — protected by compensating controls reviewed and approved by our Qualified Individual, as permitted by the FTC Safeguards Rule.
  • Backups containing personal information are encrypted at rest, and access to backups is limited to authorized personnel.

Access Controls

  • Access to systems containing personal information is restricted to personnel with a documented business need, on the principle of least privilege.
  • Authentication to internal systems requires unique user credentials and multi-factor authentication where available.
  • Access permissions are reviewed periodically, and access is revoked promptly when no longer needed (for example, on personnel changes).
  • Administrative access to production infrastructure is logged and monitored.

Application and Infrastructure Security

  • We host our infrastructure on cloud providers that publish recognized third-party security attestations (such as SOC 2 Type II) for the underlying data-center and managed services we use, and we evaluate those attestations as part of our vendor diligence.
  • We follow secure software development practices, including code review, dependency monitoring, and routine vulnerability scanning.
  • We monitor our systems for security events and maintain logging to support investigation and response.
  • We maintain a documented change-management process for system and code changes that affect the security of customer information.

Vendor Diligence

Before sharing personal information with any third-party service provider — funding lenders, infrastructure providers, identity verification vendors, analytics partners — we evaluate that provider's security and privacy posture. We bind providers by written agreements that include confidentiality, security, and data-handling obligations consistent with applicable law.

Incident Response

We maintain a written incident response plan to identify, contain, investigate, and remediate suspected security incidents. If we determine that a security incident involving your personal information has occurred and applicable law requires notification, we will notify you and the relevant authorities consistent with the timing and content requirements of the applicable law. This includes, where applicable, reporting qualifying notification events to the Federal Trade Commission within 30 days as required by the FTC Safeguards Rule (16 C.F.R. § 314.4(j)), and providing notice to affected individuals and state regulators as required by state breach-notification statutes.

Your Role in Keeping Information Safe

Security is shared. Please help protect your information by:

  • Choosing a strong, unique password for your application portal and not sharing it with anyone;
  • Keeping your devices and browser up to date;
  • Verifying the URL (clearvaluelending.com) before entering sensitive information;
  • Being skeptical of unexpected calls, texts, or emails asking for sensitive information — we will never ask for your full Social Security number, full bank account number, or one-time codes by unsolicited text or email;
  • Reporting suspicious activity to hello@clearvaluemoney.com.

Reporting a Vulnerability

If you believe you have found a security vulnerability in our Services, please report it by emailing hello@clearvaluemoney.com. Please include enough detail for us to reproduce the issue. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate. We commit to acknowledging legitimate reports promptly and to working with researchers in good faith.

No Guarantee of Absolute Security

No system is impenetrable. While we maintain reasonable safeguards, we cannot guarantee that personal information will not be subject to unauthorized access, disclosure, or alteration. By using the Services, you acknowledge this risk and accept the limitations described in our Terms of Use.

Contact

Security questions: hello@clearvaluemoney.com. Privacy questions: hello@clearvaluemoney.com.

https://clearvaluelending.com/security