Security & Privacy

Last updated: July 8, 2026

This page is maintained by TJ Marshall Consultant Group to answer common security and privacy questions about LendLink CPA. It describes the controls that are in place today. Security is a shared responsibility: we operate the platform securely, and clients help by protecting their own account credentials.

Controls in place

Authentication

Accounts are protected with email/password and Google sign-in. Every request is verified server-side before any data is returned, so identity is never trusted from the browser alone.

Role-based access control

Clients, CPAs, underwriters, and administrators each see only what their role allows. Roles are stored separately from user profiles and checked on the server to prevent privilege escalation.

Row-level security

Database access is enforced by row-level security on every table. Applications, documents, and credit reports are readable only by the owner, the assigned underwriter, and administrators.

Encrypted, private storage

Uploaded identity and income documents live in a private storage bucket that is never publicly accessible. Data is encrypted in transit and at rest.

Input validation

Application and profile data is validated on the server before it is stored, reducing the risk of malformed or malicious input reaching the database.

Secret management

API keys and integration credentials are stored as server-side secrets. They are never exposed in the browser or embedded in client code.

Built on SOC 2 Type II-compliant infrastructure

LendLink CPA runs on managed cloud infrastructure that maintains a SOC 2 Type II attestation covering the underlying hosting, database, authentication, and storage services. This describes the compliance posture of the infrastructure we build on — it is not, on its own, a certification of TJ Marshall Consultant Group or of LendLink CPA as an application. Independent certification of the application or organization would require a separate audit.

How your data is handled

  • We collect only the account, application, and document information needed to submit, route, and track loan applications.
  • Sensitive fields such as Social Security numbers and uploaded identity and income documents are restricted to the people authorized on a given application.
  • We do not sell your personal information.
  • Application data is retained for as long as your account is active and as needed to meet legal, tax, and lending recordkeeping obligations. You may request deletion, subject to those requirements.

For full details on what we collect and how we use it, see our Privacy Policy.

Report a security concern

If you believe you have found a security vulnerability or have a privacy question, contact us at security@lendlinkcpa.app. We take reports seriously and will respond as quickly as we can.