Client Login

Security and responsible information handling

A financing experience should earn trust at every step.

LeasePoint’s public website, financing experiences, operating procedures, and support channels must protect sensitive information through clear system boundaries, approved access, responsible data use, and verified controls. This page explains the current approach and where to report a concern.

Reviewed
Response headers verified September 6, 2026
Scope
new.leasepoint.io public marketing site
Architecture
Public site kept separate from operational and internal systems
Reporting
help@leasepoint.com, subject “Security Inquiry”
01

Scope matters

Security claims should identify the system they describe.

The public marketing site is intentionally separate from operational products, customer portals, vendor technology, CRM systems, underwriting systems, and internal data.

Scope 1

Public marketing site

Public editorial pages, navigation, consent controls, public forms, and approved marketing integrations.

Scope 2

Buyer and account experiences

Approved application, document, signature, verification, status, support, and account workflows.

Scope 3

Vendor technology

Approved Signal, Apply, Partner, CRM, reporting, and program-management experiences.

Scope 4

Internal and third-party systems

Underwriting, operations, servicing, support, analytics, hosting, identity, communications, document, banking, and other approved systems.

02

Public-site security approach

The current public-site controls, exactly as verified.

These controls describe this public marketing site as observed in the September 6, 2026 response-header and route verification. A verified public-site control is not proof of a different product or operational system.

HTTPS

The public site is delivered over HTTPS.

Verified · September 6, 2026

Strict transport

The site sends HTTP Strict Transport Security with a two-year policy and subdomain coverage.

Verified · September 6, 2026

Content Security Policy

The site restricts script, style, image, connection, frame, form, and object sources to the published allowlist.

Verified · September 6, 2026

Framing protection

Response headers deny framing and the policy also prevents unauthorized ancestors.

Verified · September 6, 2026

Content-type protection

The site prevents MIME-type sniffing.

Verified · September 6, 2026

Browser-permission limits

Camera, microphone, geolocation, and payment access are disabled for the public site.

Verified · September 6, 2026

Referrer behavior

A strict origin-based policy limits information included in cross-origin requests.

Verified · September 6, 2026

Environment-specific indexing

The production site is indexable, while isolated preview deployments send no-index directives.

Verified · September 6, 2026
03

Data handling principles

Six rules that govern how information moves.

Collect for a defined purpose

Ask for information only when the user, workflow, purpose, owner, and approved destination are clear.

Use the correct system

Applicant, identity, banking, credit, financial, ownership, document, and account information belongs in approved secure workflows.

Limit access

Access should follow role, purpose, program, system authorization, and applicable requirements.

Separate public and operational systems

The marketing site should not contain credentials, underwriting logic, applicant records, private pricing, customer documents, or internal identifiers.

Retain deliberately

Retention and deletion should follow the approved legal, privacy, security, product, and operational requirements for the applicable system.

Share carefully

Third-party sharing requires a defined purpose, appropriate access, approved terms, a documented data flow, and applicable privacy treatment.

04

Applicant information

Sensitive information belongs in the approved financing path.

Review the destination, request, authorization, and privacy information before submitting sensitive data. If a request appears unusual, stop and use a known LeasePoint route.

Provide through approved secure channels

  • The designated LeasePoint application experience
  • An authenticated account or document workflow
  • A secure destination provided by an authorized LeasePoint contact
  • A verified support or security route for the stated purpose

Do not provide through

  • General marketing contact forms
  • Public website comments or social media
  • Unapproved text messages or ordinary email attachments
  • A request from someone outside the approved financing process

Applicant reminder. A financing request should never require you to publish or casually message sensitive information.

Apply for financing Opens in a new tab.
05

Access and role boundaries

Each role receives the access its purpose requires.

Business buyer

Uses only the approved application, document, support, status, and account experiences available for the relationship.

Vendor representative

Receives permitted referral and follow-up context without restricted applicant, underwriting, banking, document, pricing, or account information.

Vendor manager or program owner

Receives approved program-level or role-based information needed for the defined program purpose.

LeasePoint user

Access depends on job responsibility, system authorization, approved purpose, and applicable policy.

Integration

CRM, identity, document, banking, messaging, analytics, and other connections should receive only the minimum approved access for their documented purpose.

07

Third-party and integration responsibility

A connected workflow still needs controlled boundaries.

Before an approved service carries information, its purpose, system boundary, access, retention, notice, and issue path must be understood.

  • What information is shared?
  • Why is it needed?
  • Which system sends and receives it?
  • Who can access it?
  • How is access revoked?
  • How long is it retained?
  • Which consent or notice applies?
  • How is a security or privacy issue reported and investigated?
08

Privacy and choices

Security and privacy are connected, but they are not the same.

The Privacy Policy describes personal-information practices. The Cookie Notice and Privacy Choices explain website tracking and available choices.

09

Report a security concern

Report suspected vulnerabilities privately.

Do not post suspected vulnerabilities, exposed credentials, applicant information, customer information, or security evidence in a public issue, review, social post, or discussion forum.

Report a security concern

Include when safe

  • Your contact information
  • The affected LeasePoint URL, message, or product
  • A concise description of the concern
  • The date and time observed
  • Browser, device, or environment context
  • Whether credentials or sensitive information may be exposed

Do not include

  • Real applicant or customer data
  • Credentials, tokens, secret keys, or complete financial information
  • Destructive proof or testing that degrades service
  • Public disclosure before LeasePoint has a reasonable opportunity to investigate

This page does not promise a response or remediation time.

Trust documentation

Need security information for vendor review?

Qualified vendor, partner, and procurement teams may request current security, privacy, architecture, or control information relevant to the proposed program and system scope. Availability, confidentiality, and response depend on the request and approved process.

Request security information
10

Claims and evidence

Precision is part of trust.

They are not presented as a certification. Unless current scoped evidence and approved wording are available, this page does not claim:

  • A SOC 1 or SOC 2 certification or examination
  • An ISO 27001 certification
  • PCI DSS compliance
  • HIPAA compliance or business-associate status
  • GLBA, CCPA, GDPR, or other legal compliance conclusions
  • A specific encryption algorithm or key-management model
  • Continuous or 24-hour monitoring
  • A completed penetration test
  • A specific incident-response or recovery time
  • A bug-bounty or safe-harbor program
  • A particular uptime or availability level
  • Identical controls across every LeasePoint system
11

Frequently asked questions

Answers to common security questions.

Is the public marketing site the same system as the application or underwriting platform?

No. LeasePoint treats the public marketing site as separate from buyer applications, account experiences, vendor technology, CRM systems, underwriting systems, and internal data. A control verified here is not evidence for a different system.

Should I send sensitive application information through the contact form?

No. Use the approved application or another secure channel specifically provided by LeasePoint. A general inquiry can identify the topic without including sensitive information.

Can a vendor representative see applicant credit information?

No general access is implied. Vendor visibility depends on role, purpose, consent, program, system, and applicable requirements. Restricted lending information remains protected.

Does LeasePoint claim a security certification on this page?

No. LeasePoint names a certification or examination publicly only when current, scoped evidence and approved wording are available for the system being described.

How should I report a suspicious request or possible vulnerability?

Stop before providing more information. Contact LeasePoint through the published security address and describe the request or issue without including real applicant data, credentials, or destructive proof.

Can a vendor or procurement team request security documents?

A qualified team may request current security, privacy, architecture, or control information through the approved trust-document process. Availability, confidentiality, scope, and response depend on the request and applicable review.

12

Security evidence state

A dated snapshot with a defined review cadence.

Verification is a dated observation, not a permanent guarantee. Production configuration and system scope are rechecked before publication and on a defined review cadence.

Verified on September 6, 2026

  • HTTPS
  • Strict transport
  • Content Security Policy
  • Framing protection
  • Content-type protection
  • Browser-permission limits
  • Referrer behavior
  • Environment-specific indexing

Not claimed without approved evidence

  • A SOC 1 or SOC 2 certification or examination
  • An ISO 27001 certification
  • PCI DSS compliance
  • HIPAA compliance or business-associate status
  • GLBA, CCPA, GDPR, or other legal compliance conclusions
  • A specific encryption algorithm or key-management model
  • Continuous or 24-hour monitoring
  • A completed penetration test

Define the system, scope, and evidence your review actually requires.

Request security information