Calculator data stays in the browser

Funding-gap, loan-cost, four-year borrowing, and offer-comparison inputs are calculated locally. College Loan Finder does not ask for or store a Social Security number, date of birth, income documentation, credit report, FAFSA credentials, bank credentials, passport, visa document, or loan application.

Outbound attribution

Provider visits can create a random click identifier, first-party session identifier, provider, placement, product, campaign fields, referring path, timestamp, and a keyed client hash. The identifiers are not intended to identify a borrower. The attribution cookie expires after 30 days.

Privacy controls

A browser can disable optional attribution on the privacy choices page. College Loan Finder also honors the Global Privacy Control signal for outbound attribution by avoiding the attribution cookies and client hash while retaining only a limited aggregate event.

Application handoff

Sensitive application information should be entered only on the authorized lender or marketplace site after the user verifies the destination. College Loan Finder uses an HTTPS-only allowlist for its provider redirects and does not accept arbitrary destination URLs from a visitor.

Operational safeguards

The production configuration and attribution data live outside the public document root with restricted permissions. HTTPS, HSTS, frame blocking, MIME sniffing protection, a restrictive permissions policy, and a content security policy are applied by the HostGator release.

Responsible reporting

Report a suspected security issue through the contact page without including exploit details that could harm users. We will provide a safer submission path if sensitive evidence is required.