Security and trust

Intelligent banking requires visible boundaries.

Lenz separates financial truth, product workflows, intelligence, and execution so helpful software does not become uncontrolled software.

  1. 01Financial systems of record
  2. 02Permissioned product state
  3. 03Lenz intelligence
  4. 04Policy and approval
  5. 05Banking execution
  6. 06Audit history

Financial integrity

Money stays deterministic.

Clients do not write the ledger directly.

Financial writes are permissioned and auditable.

Historical events are corrected through reversals or adjustments—never edited in place.

Pending, submitted, processing, settled, returned, failed, and reversed remain distinct states.

Customer funds and Lenz corporate funds are never represented as commingled.

Intelligence boundary

Lenz can prepare. It cannot invent financial truth.

Material amounts come from permitted systems and calculations, not generated text.

Intelligence tools are finite and organization-scoped.

Models do not call the bank, ledger, or signer directly.

Prepared actions retain normal policy and approval paths.

Company autonomy settings are explicit and revocable.

Identity and access

The right person, proven, with the right permissions.

Passkeys where available, with password and verification controls.

Customer and workforce sessions are strictly separated.

Role-based permissions across founder, CFO, finance, and employee responsibilities.

Requester and approver separation on money movement.

Step-up verification for high-value or new-beneficiary actions where applicable.

Sensitive data

Identity data is handled as restricted material.

BVN, NIN, and identity documents are encrypted, masked, and stored separately.

Credentials, OTPs, and tokens never appear in application logs.

Files live in access-controlled storage with logged access.

Retention and deletion follow stated policy.

Integrations

Connections are scoped, visible, and removable.

Requested scopes are shown before connecting.

Read and write behavior is stated per integration.

Last sync is always visible.

Disconnecting removes access.

Banking and custody

Who provides what, in writing.

Banking services and accounts are provided through disclosed licensed partners. The banking service provider, account issuer, custody model, and complaint escalation path are disclosed during onboarding and in the relevant product surfaces—not buried in a footer.

Responsible disclosure

Found a vulnerability? Tell us privately.

If you believe you have found a security vulnerability, report it privately so the team can investigate without putting customers at risk.

security@lenzfinance.com

See your company through Lenz.

Open a free workspace and experience a clearer way to understand, manage, and move company money.

It costs nothing to try. Banking activation is subject to company verification and partner approval.