# LemFi > LemFi (formerly Lemonade Finance) is a London-headquartered cross-border payments and > remittance fintech built for immigrant communities. It operates as a regulated Electronic > Money Institution in the UK and, in the US, through Pomelo Two US LLC (NMLS 2523778), > registered with FinCEN as a money services business. Consumers use LemFi's iOS and Android > apps to hold multi-currency balances, receive local bank details in their country of > residence, request money, buy eSIM data, and send transfers to 30+ receive markets across > Africa, Asia, Europe and Latin America. ## Agent-relevant summary LemFi is a CONSUMER APP COMPANY, not an API provider. As of 2026-08-25 there is no public developer program: no developer portal, no API reference, no OpenAPI/AsyncAPI/GraphQL/gRPC/ WSDL contract, no SDKs on any package registry, no CLI, no sandbox, no webhooks catalog, no MCP server, no A2A agent card and no llms.txt of LemFi's own. An agent cannot transact with LemFi programmatically. The only LemFi-controlled API host found — api.lemonade.finance, an AWS API Gateway — is the private backend for the mobile apps and answers 403 {"message":"Missing Authentication Token"} to anonymous callers. This file is GENERATED by API Evangelist from LemFi's public pages. It is not published by LemFi and does not live at https://lemfi.com/llms.txt (which returns 404). ## Products - [International money transfer](https://lemfi.com/en-us/international-money-transfer): send money to 30+ receive markets via direct integrations with tier-1 local banks. - [Request money](https://lemfi.com/en-us/request-money): payment request links between users. - [eSIM](https://lemfi.com/en-us/esim): mobile data plans purchasable in the LemFi app. - [Invite and earn](https://lemfi.com/en-us/invite-and-earn): referral programme. ## Security and compliance - [Trust center](https://trust.lemfi.com/): Secureframe-hosted. Names SOC 2 Type II, PCI DSS Level 1, ISO 27001 and GDPR. Certificates, the SOC 2 bridge letter and the PCI DSS AOC are released on request; the privacy policy and terms are public. - [Vulnerability disclosure policy](https://lemfi.com/en-us/legal/vulnerability-disclosure-policy): managed by Inspectiv, submissions at https://client.inspectiv.com/vdp/lemfi/submit-report. Safe harbour for good-faith research; minimum 90-day disclosure window; disclosure-only, no bounty. In scope: lemfi.com, the Android and iOS apps, app.lemonade.finance. - [Security](https://lemfi.com/en-us/security): regulator and licence disclosures. - No RFC 9116 security.txt is served (https://lemfi.com/.well-known/security.txt returns 404). - Domain posture (probed 2026-08-25): TLS 1.3, HSTS max-age 31556926, SPF present, DMARC p=reject, no DNSSEC, no CAA records. ## Company - [About](https://lemfi.com/en-us/about) - [Contact](https://lemfi.com/en-us/contact-us) - [Help center](https://support.lemfi.com/hc/en-us) - [Blog](https://blog.lemfi.com/) - [Careers](https://jobs.ashbyhq.com/lemfi) ## Legal - [Terms and conditions](https://lemfi.com/en-us/legal/terms) - [Privacy policy](https://lemfi.com/en-us/legal/mobile-privacy) - [Legal hub](https://lemfi.com/en-us/legal) ## Optional - Locales served: en-us, en-gb, en-ca, en-ie, en-ng, fr-fr, fr-ca, fr-be, de-de, es-es, it-it, pt-pt, pt-gb, zh-us. lemfi.com 302s the bare root into a locale prefix, which is why unprefixed paths such as /llms.txt and /.well-known/* redirect before 404ing.