Loading this page.
Printed from dollarloanz.com/security. Dollar Loans LLC d/b/a Dollar Loanz.
Skip to contentLoading this page.
Security
Written twice on purpose. The plain version first, then the mechanics underneath — including every control we have not built yet, marked as such.
In plain English
Five categories. Each one says why we need it, who outside this company it reaches, and how long it stays.
Your name, date of birth, address, email and phone number.
Bank account details, income and employment information.
The VIN, the title, photographs, mileage and its condition.
Photographs of your title, your driver’s license and your insurance.
Your device, browser and the pages you opened while logged in.
The short version
Read this list once. Every line on it is also a description of how somebody would pretend to be us — so if any of it happens to you, it is not us, and you can put the phone down.
We will never ask you for your online banking password.
We never need it. Anyone asking for it is not us.
We will never ask you to pay a fee before you are funded.
Advance-fee demands are the most common title funding scam there is. Our fee is charged on the agreement, after the money reaches you, and it is on screen before you sign.
We will never phone you and ask you to read back a one-time code.
That code is how somebody else gets into your account. We send it to you; we never ask for it back.
Nobody working for us will ask you to drop off the car or hand over your keys.
If someone does, it isn’t us. Tell us: write to us at support@dollarloanz.com or from the Contact page, and we confirm in writing within one business day that we got it. You can also call (833) 404-5626. We haven’t published opening hours yet, so a call may not be answered. You keep the vehicle and keep driving it while the agreement is in place. If the payments aren’t made as the agreement says, the vehicle can be repossessed.
We will never run a credit check just to show you a price.
The calculator asks for two numbers and shows the cost of that example. It does not ask who you are, and it is not an offer.
We will never text or email you a link and ask you to log in through it.
If you get one, do not use it. Type dollarloanz.com into your browser yourself, or forward the message to support@dollarloanz.com and we will tell you whether it came from us.
We will never quote you a rate that leaves out half the price.
S2 Funding LLC's rate on its own is not the annual percentage rate of this agreement. The annual percentage rate counts our fee and S2 Funding LLC's interest, so it is the figure to compare.
The same list on its own page, with the only channels that are ours and what to do if somebody claiming to be us has already contacted you: fraud and scams. If an agreement was taken in your name, that is a different problem with its own page: this isn’t my account.
The mechanics
Open a row for the technical detail. An in-place control names the evidence you could go and check; a planned one names the date we are aiming at. Neither is optional.
Everything we think matters, whether or not it flatters us.
Each one names something a sceptic could go and verify.
Most of these land before the first real application is accepted.
Read the planned column first
Photos of your title, your driver’s license and your insurance — the most sensitive things you send us.
How it actually works
The capture control reads sharpness, resolution and glare in the browser before anything leaves the device, and re-encodes images down to a 2000px longest edge. A file the browser cannot decode is passed through untouched rather than silently mangled.
What you could check
src/components/product/form/file-dropzone.tsx — quality checks and downscaling run client-side, before upload.
How it actually works
A dedicated object store behind a BlobPort with per-object keys, server-side encryption and time-limited signed read URLs. No document store is wired today; the application flow currently runs against mock adapters.
When we are aiming to have it
Before the first real application is accepted.
How it actually works
The 7-year obligation attaches to the transaction records themselves. Material outside that — an abandoned application, a document you replaced, marketing preferences — has a much shorter life and should be expired automatically rather than kept by default. The expiry job is built and tested (scripts/retention-sweep.mjs, src/__tests__/retention-sweep.test.ts): abandoned applications and handled messages carry an expiry date and the sweep deletes past it. It is not yet running on a schedule against a production database, because there is no production database yet, and the periods it applies are proposals rather than decisions — so this row stays at planned until both are true.
When we are aiming to have it
Alongside the first production data store.
Getting in, staying in, and what happens if somebody else tries.
How it actually works
Requests to your account area and to the internal admin area are checked before the page is built: the session token has to carry a valid Ed25519 signature made with our own key, and the internal area additionally requires a permission no customer session carries. A cookie that merely exists gets nobody in, and a missing or unreadable key means nobody is logged in rather than everybody. A member of staff logs in the same way you do, on an account that was opened with the internal permission from a terminal; nothing on the public site can grant it.
What you could check
proxy.ts — the gate verifies the session signature for /portal, /dashboard and /admin; src/__tests__/auth-gate.test.ts exercises it against forged, expired and cross-tenant tokens; src/__tests__/demo-account.test.ts proves the demonstration session never carries the internal permission.
How it actually works
WebAuthn as the primary factor, with a one-time code as the recovery path and no password at all. A passkey is discoverable and user-verified — it lives on your device, needs your face, fingerprint or PIN, and is bound to this site — and a signature counter that goes backwards is refused as a cloned device. The code is six digits from a cryptographic random source, stored only as a keyed hash, good for ten minutes and one use; five wrong answers burn it, ten in fifteen minutes pause the account and tell you. Asking for a code answers the same way, in the same time, whether or not the details are on an account, so the log-in page cannot be used to find out who holds an agreement with us. A session that came in with a code can read the account and send us documents; moving money needs a passkey. Codes leave the building through a messaging carrier, which is still being selected (see the subprocessor list): until one is contracted, a deployment cannot switch log-in on, and the log-in page says so rather than pretending.
What you could check
src/adapters/sign-in/sign-in-service.ts (the rules, once, over either store), src/adapters/postgres/postgres-sign-in-adapter.ts and db/schema/0003_identity.sql, the routes under src/app/api/auth/passkey/ and /api/auth/login and /api/auth/verify, and src/__tests__/sign-in-contract.test.ts, passkey.test.ts and login-verify-routes.test.ts, which drive both stores and every route with a software authenticator.
How it actually works
The Security page in your account lists every live session with when it started, when it was last used and when it will end for good, and the log-out page has a single "Log out everywhere" control that ends all of them, including the one you are on. A device is shown as a fingerprint rather than a place, because we keep a one-way hash of the browser and the network address and never the values themselves. Ending one session from the list, rather than all of them, is not built yet, and the page says so.
What you could check
src/app/portal/security/page.tsx reads the list from the session store for the logged-in subject only; src/app/api/auth/logout/all/route.ts revokes every family for the subject from the verified signature; src/__tests__/session-store-contract.test.ts and auth-refresh-rotation.test.ts prove the store behind both.
How it actually works
An append-only record behind an AuditPort covering every servicing action, every document state change and every access by a member of staff, rendered for the customer rather than kept for us.
When we are aiming to have it
With the case tracker.
The parts you never see, which is exactly why they get written down.
How it actually works
No analytics script, advertising pixel, session recorder or third-party tag manager is loaded on any page. Fonts are served from this origin rather than a font CDN, so even that request does not leave.
What you could check
No third-party script tag exists anywhere in src/. Verified by scan on 2026-09-14.
How it actually works
The cost engine is a pure function bundled with the page. There is no network request behind any slider, and no application record is created by using one. State lives in the URL so a quote is shareable by text message — which means you choose when we see it.
What you could check
src/lib/calculator.ts and the calculator routes contain no network call of any kind.
How it actually works
TLS 1.3 with HSTS including subdomains and preload, a content security policy that pins script sources, and the usual frame and content-type protections. The site is served over HTTPS today; the strict-transport and content-security headers are not yet configured, so this row stays at planned.
When we are aiming to have it
At first production deploy.
How it actually works
A written security review and a data processing agreement before a processor goes live, and a public register naming them. The register is published. One service is already live on it — NHTSA, for the free VIN decode and recall check — and it is named there with no contract behind it, because a federal agency does not offer one to sign. Every commercial processor is still unselected, which is exactly what the register says.
When we are aiming to have it
Each entry as it is contracted.
How it actually works
A scoped penetration test of the public site, the application flow and the customer portal by an outside firm, with the report date and the remediation status published here afterwards. Nobody outside this company has tested it yet.
When we are aiming to have it
Before the portal opens to customers.
Most breaches are not clever. They are somebody inside, with more access than the job needed.
How it actually works
Role definitions in configuration rather than in code, with document access granted per case and expiring, and every access written to the audit log the customer can read.
When we are aiming to have it
With the servicing console.
How it actually works
Maker-checker approval on payment reversals, balance adjustments, payoff overrides and lien releases, with both names on the record.
When we are aiming to have it
With the servicing console.
How it actually works
A written incident runbook with severity levels, a named owner, notification timelines that meet the Texas requirements, and a public post-incident note for anything that affected customers. The policy is drafted and not yet exercised.
When we are aiming to have it
Before the first real application is accepted.
Control register last reviewed
The limit of this page
Which is worth saying out loud, because it is the single most important caveat on everything above.
Every “in place” row above is our own assessment of our own work. We have named the evidence for each one so you can weigh it rather than trust it, but that is not the same thing as an independent firm having gone looking, and we are not going to blur those two into one reassuring sentence.
A scoped penetration test of the public site, the application flow and the customer portal is planned before the portal opens to customers. When it has happened, the date and the remediation status land on this page — including anything that was found.
In the meantime, the way to find out whether we are any good at this is to look yourself. The policy below says what you may test, what we promise in return, and how quickly we will answer.
There is a published disclosure policy with real response times and safe-harbor language behind it. Researchers welcome.
Registration status
Texas credit access business registration: not yet issued
Check our registration status with the Office of Consumer Credit CommissionerRegulator
Office of Consumer Credit Commissioner
2601 North Lamar Boulevard, Austin, TX 78705
Consumer helpline (800) 538-1579
$2,000 to $50,000. The amount depends on the vehicle and your application. Full fee schedule at /occc. These disclosures are effective September 14, 2026.