How your data is handled.

Starting with the part that matters most: card numbers never touch our systems. Then everything else, in the open.

Card data

Card data never touches Lombard's systems. Card numbers are captured and stored by our processing partner, a registered ISO of Esquire Bank, N.A. and Commercial Bank of California, which maintains PCI DSS compliance. Lombard sees settlement records — never a card number.

The standard everything is built to

These are non-negotiables, enforced in the platform's foundations — not policies added later:

No card data, by architecture

There is no code path in Lombard's systems that accepts, stores or transmits a card number. Not a policy — an absence. Card capture lives entirely with the processing partner.

Application-layer encryption for sensitive fields

Bank details and government identifiers are encrypted before they reach the database — not just disk encryption underneath. No plain column, ever, including in development.

Append-only financial records

Money records are never updated or deleted. Corrections are new entries, so the history is always the whole history — and your ledger can always be re-derived from it.

Audit logging on money and auth paths

Every state-changing action on a money or authentication path writes an audit record. Who, what, when — kept from the first day the path exists.

A narrow public surface

The public site can submit an application or a contact message to an access-restricted database, and nothing else. Public database roles are fully revoked; every table has row-level security enabled with no public policies.

We hold what we need, and no more

Your business identity, contact details, and the records underwriting and remittance actually require — encrypted at rest, readable only by Lombard. Nothing from a form is ever written to a log, and analytics load only with your explicit consent.

Certifications

Lombard holds none. When an audit is completed, it will be named here with its date and scope — not before.