EZBudget™
Security Governance Policy Packet
Official policy index for Plaid and partner security due diligence submissions.
Included Policy Documents
| Document | ID | Questionnaire Coverage | Policy URL |
|---|---|---|---|
| Information Security and Governance Policy | EZB-ISG-001 | Documented IS policy and operational security program | /policy/InformationSecurityGovernance/ |
| Security Risk Assessment Policy and Program | EZB-SRA-001 | Documented risk assessment policy with annual cadence | /policy/RiskAssessmentPolicy/ |
| Security Audit and Assurance Policy | EZB-AUD-001 | Independent audits + internal assessments (SOC 2 / ISO-aligned) | /policy/AuditAssurancePolicy/ |
| Penetration Testing Policy and Program | EZB-PEN-001 | Application and infrastructure pen-testing by independent testers | /policy/PenetrationTestingPolicy/ |
| Access Control Policy | EZB-ACM-001 | Documented access control policy and RBAC | /policy/AccessControlPolicy/ |
| Consumer Multi-Factor Authentication Policy | EZB-MFA-001 | Phishing-resistant MFA before Plaid Link on web/mobile | /policy/ConsumerMfaPolicy/ |
| Critical Systems Multi-Factor Authentication Policy | EZB-MFA-002 | Phishing-resistant MFA for critical financial data systems | /policy/CriticalSystemsMfaPolicy/ |
| Logging and Monitoring Policy | EZB-LOG-001 | Audit trails and logs for material production events (Plaid Q22) | /policy/LoggingMonitoringPolicy/ |
| Data Retention and Deletion Policy | EZB-RET-001 | Defined retention, deletion, and periodic review (Plaid Q25) | /policy/DataRetentionDeletionPolicy/ |
| Change Management and Secure SDLC Policy | EZB-CHG-001 | Change / release management and secure SDLC (Plaid Q27) | /policy/ChangeManagementPolicy/ |
| Vulnerability Management Policy | EZB-VUL-001 | Vulnerability identification and remediation (Plaid Q28) | /policy/VulnerabilityManagementPolicy/ |
| Endpoint Security Policy | EZB-END-001 | Workstation and production endpoint protections (Plaid Q29) | /policy/EndpointSecurityPolicy/ |
| Security Awareness Training Policy | EZB-SAT-001 | Onboarding and recurring security awareness training (Plaid Q30) | /policy/SecurityAwarenessTrainingPolicy/ |
| Incident Response Policy | EZB-IR-001 | Detection, triage, resolution, and notification (Plaid Q31–Q32) | /policy/IncidentResponsePolicy/ |
| Third Party Risk Management Policy | EZB-TPR-001 | Vendor / third-party risk program (Plaid Q33) | /policy/ThirdPartyRiskManagementPolicy/ |
Submission Guidance
Open each linked document and use Print / Save PDF to export individual policy PDFs, or print this packet index as a cover sheet for your submission bundle.
Contact: contact@deseodevelopers.com