Last updated: July 1, 2026
Guapaholics handles sensitive business and financial data on behalf of our clients, so security isn't an afterthought, it's core to how we build. This page is a plain-language summary of our program; it is not a substitute for a signed security exhibit or data processing addendum in a client agreement.
Encryption in transit and at rest, role-based access control, and PII tokenization via Skyflow for sensitive identifiers.
Least-privilege access to production systems, logging and monitoring, and vendor risk review for critical subprocessors.
Formal onboarding/offboarding for system access, and due diligence on partners like Stripe, Plaid, NAV, and Rental Kharma.
Written security and privacy policies, incident response procedures, and a defined data retention schedule.
We are building our security and availability controls toward a SOC 2 Type II audit and have not yet completed an independent audit. We do not claim SOC 2 certification until that audit is complete. Enterprise and CDFI clients can request our current control documentation and audit timeline under NDA by emailing guapaholics@guapaholics.com.
We are not currently targeting EU users directly, but we design our data-handling practices, data minimization, purpose limitation, data processing addenda with subprocessors, and honoring data-subject rights requests, to align with GDPR principles for the EU-connected data we may process on a client's behalf.
Guapaholics does not process protected health information and the Platform Services are not designed for HIPAA- covered use cases. HIPAA is not applicable to our current offerings.
Because we process nonpublic personal financial information on behalf of lending clients, we align our safeguards program with the Gramm-Leach-Bliley Act Safeguards Rule, and rely on PCI-compliant, regulated partners (Stripe Issuing, Plaid) for card and bank-data handling rather than storing raw card or bank credentials ourselves.
We use the following categories of subprocessors to deliver the Platform Services. A current, detailed subprocessor list is available to clients under their Master Services Agreement.
To report a security vulnerability, request our security questionnaire, or ask about the status of our SOC 2 audit, email guapaholics@guapaholics.com. Please do not include sensitive personal or financial data in your initial report.