Executive Summary
AI-generated analysis for Yodlee
Yodlee (yodlee.com), a financial data aggregation and analytics platform operating as a subsidiary of Envestnet, presents a High Risk (Tier 2) profile based on independently sourced evidence gathered at the time of this assessment. Positive signals include:
Key Findings
- A 27-year-old domain registered since 1999, indicating a long-established online presence
- A valid TLS 1.3 certificate issued by DigiCert Inc, expiring July 2026
- Clean IP reputation with a 0% abuse confidence score across the past 90 days
- No malware, phishing, or unwanted software flags from Malware detection service
- No sanctions matches across OFAC, EU, and UN watchlists
- No adverse media detected in the past 12 months
- A SOC 2 compliance claim referenced in a vendor-published Security FAQ document
- The domain has been active LEI-registered entity (YODLEE, INC.) in the US-DE jurisdiction Significant concerns identified in this investigation include the detection of multiple sensitive services — including FTP (21), SMTP (25), MySQL (3306), RDP (3389), and Elasticsearch (9200) — on IP addresses associated with Yodlee's domain, though the infrastructure context (Cloudflare/Incapsula CDN edge) warrants further clarification before treating these as direct backend exposures. The marketing site (yodlee.com) received a poor HTTP security scanner HTTP security grade of D- (25/100), with missing Content-Security-Policy and X-Frame-Options headers. No public subprocessor list was identified, limiting third-party supply chain visibility. Yodlee's AI data usage policy does not clearly state whether customer data is used for AI model training. The LEI registration for YODLEE, INC. has lapsed, which may indicate a gap in regulatory filing maintenance. No ISO 27001 certification was found in independent registry searches, and the HITRUST directory showed a possible but unconfirmed match requiring manual verification. Given the combination of exposed sensitive service ports, missing security headers, absence of subprocessor transparency, and unclear AI training practices — all material concerns for an organization handling financial data — a conditional approval posture is warranted pending resolution of the items identified below.
Independence Statement
All evidence presented in this report was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation or input.