Security and how to spot a loan scam

How your information is protected, what we will never ask you for, and how to verify that a lender contacting you is genuine.

Encryption256-bit TLS
Bank connectionsRead-only
Upfront feesNever requested
Data salesNone

How your data is protected

  • Encryption in transit. Every page and every document you submit is served over TLS with 256-bit encryption. Look for the padlock and confirm the domain reads exactly truelinkfinance.com before entering anything.
  • Encryption at rest. Personal and financial data is encrypted in storage, and access is restricted to staff who need it for a specific task.
  • Read-only bank connections. When you link an account to verify income, the connection is read-only. It cannot be used to move money out, and we never see or store your online banking password.
  • Access controls. Staff access is role-based and logged. Nobody can view your full account details without a business reason tied to your loan.
  • Retention. Records are kept for the period consumer lending law requires and then destroyed. Details are in the privacy notice.

Our handling of financial data is governed by the Gramm-Leach-Bliley Act, which requires us to explain what we collect, why, and who it is shared with. We do not sell your information; the reasoning is on how we make money.

What we will never ask you for

Four things that mean it is not us

We will never ask for a fee, a gift card, a wire transfer, or cryptocurrency before funding your loan. We will never ask for your online banking password. We will never guarantee approval before reviewing your application. We will never pressure you to decide within minutes.

Every one of those is a defining feature of an advance-fee loan scam, which the Federal Trade Commission has warned about for years. A legitimate lender deducts what it is owed from the loan or the scheduled payments. It does not ask you to send money first.

How to tell a real lender from a fake one

  1. Ask for the NMLS IDThen search it at nmlsconsumeraccess.org and confirm the legal name matches the website and the licence covers your state. Ours is on the licences page.
  2. Check the domain letter by letterScam sites clone real lenders with a hyphen, an extra letter, or a different ending. Type the address yourself rather than following a link from a text message.
  3. Look for a physical address and a working phone numberThen call it. A lender with no verifiable address is not one you should send documents to.
  4. Refuse any upfront paymentNo exceptions. Insurance fee, processing fee, good-faith deposit, and first payment in advance are all the same scam with different names.
  5. Be sceptical of unsolicited approachesWe do not cold-call, text, or message people on social media offering loans. If someone claiming to be us does, it is not us.

Protecting your own account

  • Use a unique password for your loan account, not one reused from elsewhere
  • Turn on two-factor authentication where offered
  • Check your bank statement against your payment schedule each month
  • Review your credit report free at annualcreditreport.com, the only federally authorised source
  • If you suspect fraud on your credit file, place a free fraud alert or a credit freeze with each of the three bureaus

If you think you have been targeted

Contact us at [email protected] or +1 (800) 555-0190 so we can confirm whether a communication came from us. Report the incident to the FTC at reportfraud.ftc.gov and to the Consumer Financial Protection Bureau at consumerfinance.gov/complaint. If you sent money, contact your bank immediately: some transfers can be recalled within a short window.

If someone has used your identity to apply for credit, IdentityTheft.gov provides a step-by-step recovery plan and generates the affidavit most institutions require.

Reporting a vulnerability

If you have found a security issue in our systems, email [email protected] with enough detail to reproduce it. We will acknowledge within [two business days]. Please do not access, modify, or retain other people's data while testing.

This page was last reviewed on by .