Verified Entity
Registered in the Global LEI System
Medaleon LLC holds a Legal Entity Identifier (LEI) — the globally unique, ISO 17442 code used to identify legal entities in financial transactions worldwide. Our LEI was issued by Bloomberg Finance L.P., a GLEIF-accredited issuer, and is publicly verifiable by any bank, broker, or counterparty we work with.
Being LEI-certified is more than a formality — it changes how efficiently and confidently Medaleon operates. Because our identity lives in the public GLEIF registry, banks, brokers, custodians, and prospective partners can verify us instantly and independently, which streamlines account opening, onboarding, and the due-diligence and KYC reviews that might otherwise take days. It is the same standardized identifier relied upon in regulatory reporting for securities and derivatives transactions worldwide, keeping Medaleon aligned with the transparency standards that institutional markets expect. And because a single code identifies us consistently across every jurisdiction and counterparty, it reduces the risk of misidentification, strengthens our credibility with the institutions we transact with, and reinforces the trust our investors and partners place in the firm.
Legal Entity Identifier
254900J33TXT7HC4BV22
Issued By
Bloomberg Finance L.P.
Registration Authority
Florida Division of Corporations
Oversight
Global LEI Foundation (GLEIF)
Legal Entity Identifier issued by Bloomberg Finance L.P.
Security Program
Guided by the NIST Cybersecurity Framework (CSF) 2.0
Medaleon has adopted the NIST Cybersecurity Framework (CSF) 2.0 — the framework published by the U.S. National Institute of Standards and Technology — to structure and guide our cybersecurity program. Organized around the Framework’s six core functions of Govern, Identify, Protect, Detect, Respond, and Recover, our program brings together the security policies already in place across the firm, including access management, incident response, vulnerability testing, security awareness training, and data retention and deletion, into a single governance structure overseen by our Security Program Owner. We have assessed our program against the Framework’s full set of outcomes and maintain a prioritized roadmap to close the gaps we’ve identified, with the aim of maturing our practices across every function over time. This work reflects our broader commitment to safeguarding the personal and financial information entrusted to us by our clients.
Security Registry
Listed on the CSA STAR Registry
Medaleon has completed a Cloud Security Alliance (CSA) STAR Level 1 Self-Assessment, evaluating our cloud security program against the CSA Cloud Controls Matrix (CCM) through the Consensus Assessments Initiative Questionnaire (CAIQ). Our assessment is published in the CSA STAR Registry, providing customers, institutional partners, and service providers with transparent visibility into our cloud security governance.
Our participation in the CSA STAR program complements our NIST Cybersecurity Framework (CSF) 2.0-aligned cybersecurity program and demonstrates our commitment to implementing recognized industry best practices for protecting confidential information, maintaining operational resilience, and continuously strengthening our security posture.
For institutional counterparties, the CSA STAR Registry provides a standardized and publicly accessible security assessment that can help support vendor due diligence, reduce repetitive security questionnaires, and improve confidence in Medaleon’s governance and cloud security practices. Our registration can be viewed at the CSA STAR Registry.
Banking Connectivity
Secure Banking Connectivity Powered by Plaid
Medaleon has partnered with Plaid to provide members with a secure, seamless, and trusted banking experience. Through Plaid’s encrypted and tokenized infrastructure, members can securely connect their U.S. bank accounts without sharing banking credentials directly with Medaleon.
By leveraging the trusted Plaid ecosystem, Medaleon delivers fast account verification, streamlined funding, and institutional-grade security—reinforcing our commitment to protecting client information while providing a modern, reliable investment experience.
Enterprise Security
A mature, institutional-grade security program
Medaleon’s security program is structured around recognized industry frameworks and enforced through controls governing how client information is stored, transmitted, and accessed. The following measures form the operational core of that program.
- NIST Cybersecurity Framework 2.0
- CSA STAR Level 1
- AES-256 Encryption
- TLS 1.3 Secure Communications
- Multi-Factor Authentication (MFA)
- Business Continuity & Disaster Recovery
- Vendor Risk Management
- Security Awareness Training
- Role-Based Access Control (RBAC)
- Continuous Security Monitoring