Legal
Security
Last updated · September 2026
Security claims should be checkable, so this page describes exactly what we do — and what we deliberately do not do — to keep lendmapusa.net and its visitors safe.
1. The strongest control: we hold nothing
lendmapusa.net is a fully static website. It has no user accounts, no database, no comment forms and no server-side storage of visitor information. There is no trove of personal data associated with this site to steal, because none is collected. The only place personal information can enter the picture is the third-party loan request form, which is operated by an independent network — its security practices, not ours, govern that data.
2. Transport encryption
- All traffic is served over HTTPS, and HTTP requests are redirected to HTTPS.
- We send an HTTP Strict Transport Security (HSTS) header instructing browsers to keep using encrypted connections for two years, including subdomains.
3. Response headers we send
Every page is delivered with the following hardening headers:
X-Content-Type-Options: nosniff— browsers will not second-guess declared content types.Referrer-Policy: strict-origin-when-cross-origin— outbound clicks leak the minimum necessary referrer data.X-Frame-Options: SAMEORIGIN— other sites cannot silently embed this one.Permissions-Policy— camera, microphone, geolocation, payment and USB access are disabled; the site has no reason to request them.
4. Third-party code
Two categories of third-party resources load on this site: Google Fonts (stylesheets and font files) and the loan request form script, which loads only on the application page. We load them over HTTPS from their official origins. We do not embed advertising scripts, social widgets or session-replay tools.
5. Responsible disclosure
Found a vulnerability? Email security@lendmapusa.net with enough detail to reproduce the issue. In scope: this domain, its delivered content and headers, and how the form is embedded. Out of scope: the third-party form platform itself (report those issues to its operator), denial-of-service, spam and social engineering. We ask that you avoid privacy violations and destructive testing; in return we will acknowledge your report within five business days and keep you informed through the fix. This is a goodwill program — currently no bounty is offered.
6. What we cannot promise
No website can guarantee perfect security, and we will not pretend otherwise. What we can promise: minimal data collection, the controls listed above, and prompt action on credible reports.
7. Protecting yourself
- Check for HTTPS before entering information anywhere — including the application form.
- Never send Social Security numbers or bank details by email, including to us. We will never ask for them.
- Verify a lender's license with your state regulator before borrowing — every state page here links to it.
8. Contact
Security matters: security@lendmapusa.net. Privacy matters: privacy@lendmapusa.net.