Policies governing how Koda Finance protects consumer financial data. Written for a single-operator system; each notes what changes before any wider release. Reviewed every six months.
How security is governed: architecture, zero-trust access, risk register, change management, incident response.
Roles and least privilege, access reviews, and de-provisioning.
TLS, tokens, certificates, and how credentials are stored and rotated.
What is stored, for how long, and how it is deleted.
What we collect via Plaid, how it is used, who sees it, and your choices.