Trust Center/Security policy
Information Security Policy
The umbrella security program for GroFi systems that store or process consumer data.
- Effective
- August 27, 2026
- Operator
- JRJ Group Holdings LLC D/B/A UNIFY
- Application
- GroFi · 40 Wall Street, 21FL, New York, NY 10005
1. Purpose
This Information Security Policy (ISP) is the umbrella security program for JRJ Group Holdings LLC D/B/A UNIFY’s operation of GroFi. It exists so consumer and commercial data used in underwriting is protected with defined, documented controls.
2. Scope
This ISP covers:
- The GroFi web application, admin application, and broker portal
- Production databases, object storage, email, and deal-pipeline integrations
- Staff, contractor, and broker access to those systems
- Merchant, owner, broker, and candidate personal information
3. Roles
- Management. Approves this ISP, provides resources, and reviews exceptions.
- Engineering / security owner. Implements controls, triages incidents, and keeps this policy and its child policies current.
- Staff and brokers. Use assigned accounts only, protect credentials, and report suspected incidents to security@grofi.com.
4. Policy statements
- Access is role-based and least-privilege. See the Access Control Policy.
- Identity is centralized in GroFi’s user directory. See Identity and Access Management.
- Data is encrypted in transit and sensitive fields are encrypted at rest. See Data Encryption Practices.
- Retention and deletion follow the Data Deletion and Retention Policy.
- Access is reviewed on a schedule. See Access Reviews and Audits.
- MFA is required on internal systems that store or process consumer data, and on any consumer-facing GroFi surface where Plaid Link is deployed. See the Multi-Factor Authentication Policy.
- Vulnerabilities are patched inside a defined SLA. See Vulnerability Management.
5. Asset and data handling
Production GroFi runs on hosted infrastructure (application host, PostgreSQL, and S3-compatible object storage). Secrets (database URL, field-encryption key, signing secret, object-storage credentials) are environment variables, not source control. Application documents, broker onboarding files, and job-application files use a private bucket with Payload access control enabled. Public media uses a separate bucket.
SSN, date of birth, and EIN are stored only in GroFi, encrypted, and readable by admins. They are not written to the Monday.com deal board.
6. Acceptable use
Staff may access merchant data only to underwrite, service, support, or secure a file. Data may not be copied to personal devices, unsanctioned chat tools, or spreadsheets. Brokers see only deals they own.
7. Incident response
Suspected unauthorized access, malware, lost credentials, or misdirected personal information must be reported to security@grofi.com immediately. The security owner triages, contains, documents, and, where law requires, notifies affected people and regulators. Plaid-related incidents that involve connected-account data are treated as high severity.
8. Exceptions and review
Exceptions require written management approval and an expiry date. This ISP is reviewed at least annually, and after a material incident or architecture change.