Trust Center/Security policy
Multi-Factor Authentication Policy
MFA on internal systems that store consumer data, and on consumer-facing GroFi surfaces where Plaid Link is deployed.
- Effective
- August 27, 2026
- Operator
- JRJ Group Holdings LLC D/B/A UNIFY
- Application
- GroFi · 40 Wall Street, 21FL, New York, NY 10005
1. Purpose
This policy requires multi-factor authentication (MFA) for JRJ Group Holdings LLC D/B/A UNIFY systems that store or process consumer data in GroFi, and for every consumer-facing GroFi surface where Plaid Link is deployed.
2. Internal systems (consumer data)
MFA is required on internal systems that store or process consumer data. That includes:
- GroFi staff access to the admin application used to view merchant PII
- Production hosting, database, object-storage, and email consoles
- Staff email used to receive applications, statements, or identity documents
Acceptable second factors are TOTP, platform authenticators (passkeys / WebAuthn), or an equivalent phishing-resistant factor. SMS-only OTP is not sufficient as the sole second factor for admin access to consumer PII. Shared staff passwords are prohibited.
3. Consumer-facing application where Plaid Link is deployed
Plaid Link is not enabled on a GroFi consumer-facing surface unless that surface enforces MFA (or an equivalent phishing-resistant authenticator) for the end-user session that starts Link.
That control means:
- A merchant connecting a bank account through Plaid Link on GroFi must complete MFA on GroFi (or a GroFi-controlled identity provider) in that session before Link initializes
- Plaid Link is not mounted on an unauthenticated marketing page
- If a consumer-facing flow cannot enforce MFA, Plaid Link stays disabled on that flow
GroFi still requests read-only access from Plaid. GroFi does not collect financial-institution passwords. See the Privacy Policy §§3 and 5.
4. Broker portal
Brokers authenticate with email and password, minimum eight characters, with a one-hour reset token. Broker accounts cannot open /admin and cannot read encrypted owner SSN or date of birth. MFA is required for any broker session that can initiate Plaid Link or view connected-account payloads. If a broker surface does not meet that bar, Plaid Link is not deployed there.
5. Exceptions
Temporary exceptions require written approval, a named compensating control, and an expiry not later than 30 days. There is no standing exception for Plaid Link on an unauthenticated page.