Trust Center/Security policy
Access Reviews and Audits
Periodic review of staff and broker access to systems that store consumer data.
- Effective
- August 27, 2026
- Operator
- JRJ Group Holdings LLC D/B/A UNIFY
- Application
- GroFi · 40 Wall Street, 21FL, New York, NY 10005
1. Purpose
JRJ Group Holdings LLC D/B/A UNIFY reviews access to GroFi on a set schedule so accounts that no longer need consumer data are removed.
2. Cadence
- Quarterly. Review all admin and editor accounts, production cloud consoles (hosting, database, object storage, email), and any account that can decrypt SSN, date of birth, or EIN.
- Quarterly. Review broker accounts: disable brokers who are no longer partners; confirm pending brokers have not been approved by mistake.
- On termination. Same-day disable of staff identity in GroFi and in hosted consoles.
- After incidents. Extra review of the affected system.
3. What is reviewed
- Whether each user still needs their role
- Whether brokers remain approved and active
- Whether any user can open /admin who should not
- Whether shared or generic accounts exist (they are not allowed for staff)
- Whether MFA is still enrolled on in-scope systems
4. Evidence
Each review produces a dated record: reviewer, system, accounts removed or changed, and exceptions. Records are kept for at least one year, aligned with the retention policy.
5. Audits
Management may run additional audits of access logs, failed logins, and document downloads. Findings feed the Information Security Policy annual review.