Security & Compliance

How we approach security

Last updated: July 1, 2026

Guapaholics handles sensitive business and financial data on behalf of our clients, so security isn't an afterthought, it's core to how we build. This page is a plain-language summary of our program; it is not a substitute for a signed security exhibit or data processing addendum in a client agreement.

Data protection

Encryption in transit and at rest, role-based access control, and PII tokenization via Skyflow for sensitive identifiers.

Infrastructure security

Least-privilege access to production systems, logging and monitoring, and vendor risk review for critical subprocessors.

Vendor & access management

Formal onboarding/offboarding for system access, and due diligence on partners like Stripe, Plaid, NAV, and Rental Kharma.

Policy & governance

Written security and privacy policies, incident response procedures, and a defined data retention schedule.

Compliance status

SOC 2 (Type II)

We are building our security and availability controls toward a SOC 2 Type II audit and have not yet completed an independent audit. We do not claim SOC 2 certification until that audit is complete. Enterprise and CDFI clients can request our current control documentation and audit timeline under NDA by emailing guapaholics@guapaholics.com.

GDPR-aligned data practices

We are not currently targeting EU users directly, but we design our data-handling practices, data minimization, purpose limitation, data processing addenda with subprocessors, and honoring data-subject rights requests, to align with GDPR principles for the EU-connected data we may process on a client's behalf.

HIPAA

Guapaholics does not process protected health information and the Platform Services are not designed for HIPAA- covered use cases. HIPAA is not applicable to our current offerings.

GLBA & financial-data handling

Because we process nonpublic personal financial information on behalf of lending clients, we align our safeguards program with the Gramm-Leach-Bliley Act Safeguards Rule, and rely on PCI-compliant, regulated partners (Stripe Issuing, Plaid) for card and bank-data handling rather than storing raw card or bank credentials ourselves.

Subprocessors

We use the following categories of subprocessors to deliver the Platform Services. A current, detailed subprocessor list is available to clients under their Master Services Agreement.

  • Stripe: card issuance and payment infrastructure
  • Plaid: bank-account connectivity and cash-flow data
  • NAV: business credit and trade-credit data
  • Rental Kharma: alternative rental trade-line data
  • Skyflow: PII tokenization / data vaulting
  • Cloud hosting and infrastructure providers: application hosting and delivery

Report a concern or request documentation

To report a security vulnerability, request our security questionnaire, or ask about the status of our SOC 2 audit, email guapaholics@guapaholics.com. Please do not include sensitive personal or financial data in your initial report.