Tipalti Help Center home page
  • Get started
    • Onboarding tools
    • Video tutorials
  • User guides
    • Tipalti Hub Home
      • Log in to the Tipalti Hub
      • Home for employees
      • Home for finance team
    • Tipalti AI Assistant
      • Ask the assistant
      • Common prompts
    • Administration
      • General
      • Communications
      • Bills setup
    • Multiple entities
      • Multiple entities
      • Switch entities with multi-instance setup
    • Funding
      • Funds overview
      • Manage virtual accounts
      • Fund Tipalti accounts
      • Transfer funds between accounts
      • Fund Multi-FX accounts
    • Payees
      • Add, import, and invite payees
      • Search payee information
      • Manage payee status and settings
      • iFrame/ Supplier Hub
      • Managing your payees
      • Manage actions as a payee
      • Add and review payee documents
      • Verification of payee
    • Taxation
      • US tax forms
      • Tax form expiration
      • Tax withholding
      • Certificate of No US Activities
      • Additional documents
      • Non-US tax collection
      • Tax form statuses
    • Procurement
      • New Procurement
      • Original Procurement
    • PO matching
      • What's new with PO matching
      • PO matching
      • Review PO matching
      • Updates to POs
      • Bill approval for PO-backed bills
      • Match dropship invoices
      • Handle prepayments
      • Matching process
      • Bill routing
      • Matching policies
    • Bills
      • Start using Bills
      • Manage bills
      • Approve and pay
      • How Bills works
    • Tipalti Expenses
      • Get started
      • Create and submit expenses
      • Manage and approve expenses
      • Build expense approval workflows
      • Reimburse expenses
      • Connect and manage your corporate cards
    • Tipalti Cards
      • Tipalti Cards
      • Fund your card
      • Manage cards
      • Process transactions
      • Monitor card transactions
      • Card matching
      • ERP sync
      • Credit card statement report
    • Payments
      • Submit payments
      • Manage payments
      • Schedule payments
      • Understanding payment statuses
      • Payment methods coverage: US and ROW
      • Payment methods coverage: UK and EU
      • Payment methods coverage: Canada
      • Payment error codes
      • Managing unsuccessful payments
    • Reports
      • AI-powered reports
      • Payment reports
      • Bill reports
      • Payee reports
      • Tax reports
      • User reports
    • Security practices
      • Email security
      • Business continuity practices
      • Two-factor authentication
      • Detect
  • Integrations
    • 3rd Party Apps
      • Partner Platforms
      • SSO
    • ERPs
      • Sage Intacct
      • NetSuite 2.0
      • Microsoft Business Central
      • QuickBooks
      • Xero
      • Tipalti Connect
      • Acumatica
      • SAP B1
    • File Integration
      • Configure auto-sync settings
      • Import files
      • Export files
  • Resources
    • Webinars
    • General FAQs
    • User guide FAQs
      • Payee FAQs
      • Bill FAQs
      • Card FAQs
      • PO Matching FAQs
      • Payment FAQs
      • Detect FAQs
      • Taxation FAQs
      • Administration FAQs
      • Expenses FAQs
    • ERP FAQs
  • Release notes
  • Dev docs
Sign in
  • Get started  
    • Onboarding tools  
    • Video tutorials  
    • Live training  
  • User guide  
    • Log in to the Tipalti Hub
    • Administration  
      • Administrative operations
      • User roles
    • Multiple entities
    • Funding  
      • View funds required
      • Fund Tipalti accounts
      • Fund Multi-FX accounts  
        • Currency cutoffs and validations
    • Payees  
      • Search payee information
      • Manage payee status and settings
      • iFrame/ Supplier Hub
      • Managing your payees
      • Documents review
    • Taxation  
      • US tax forms
      • Tax form expiration
      • Tax withholding  
        • Withholding rates
        • Income types
        • Tax form and entity types
      • Certificate of No US Activities
      • Additional documents
      • Non-US tax collection
      • Tax form statuses
    • Procurement  
      • System overview
      • Create and track purchase requests
      • Approve purchase requests
      • Mark goods and services as received
      • Vendor registration
      • Send PO PDF
      • Back office  
        • Set reminders
        • Run parallel PR/ vendor approval
        • Emails
        • PO PDF customization
        • Upload budget
        • Customize Procurement forms
        • Contract repository
      • Workflow integrations
    • PO Matching  
      • Matching process
      • Handle matching exceptions
      • Bill routing
      • Matching policies
      • Bill coding
      • Bill approval for PO-backed bills  
        • Approvable bills
        • Non-approvable bills
        • PO updates
      • Prepayments (NetSuite 2.0)
      • Track and match a dropship invoice  
        • Set payees up as dropship vendors
        • Upload and match a dropship invoice
    • Bills  
      • Bill flows
      • Usability
      • Add invoices
      • Manage bills
      • Add comments and files to bills
      • Bill approvers
      • Invoice processing approvals
      • Email Security
      • Tax collection in Bills
      • Bill statuses
    • Tipalti Expenses  
      • Get started
      • Create and submit expenses
      • Manage and approve expenses
      • Reimburse expenses
      • Connect your corporate cards
    • Tipalti Cards  
      • Funds flow
      • Manage cards
      • Card transactions overview
      • Process transactions
      • ERP sync
      • Credit card statement report
    • Submitting payments
    • Payment information  
      • Payment statuses defined
      • Payment methods coverage: US and ROW
      • Payment methods coverage: UK and EU
      • Payment methods coverage: Canada
      • Payment error codes
    • Reports  
      • Smart report builder
      • Payment reports
      • Bill reports
      • Payee reports
      • Tax reports
      • User reports
    • Security practices  
      • Email security
      • Business continuity practices
      • Two-factor authentication
    • Detect
  • Integrations  
    • 3rd Party Apps  
      • Partner Platforms
      • SSO
    • ERPs  
      • Sage Intacct
      • NetSuite 2.0
      • Microsoft Business Central
      • QuickBooks
      • Xero
      • Tipalti Connect
      • Acumatica
      • SAP B1
    • File Integration  
      • Configure auto-sync settings
      • Import files
      • Export files
  • FAQs  
    • General FAQs
    • User guide FAQs  
      • Bill FAQs
      • Card FAQs
      • PO Matching FAQs
      • Payment FAQs
      • Detect FAQs
      • Taxation FAQs
      • Administration FAQs
      • Expenses FAQs
    • ERP FAQs
  • Release notes
  • Dev docs
  1. Tipalti
  2. User guide
  3. Security practices
Follow

Articles in this section

  • Security practices
  • Two-factor authentication

Security practices

Tipalti's security practices are divided into two parts:

  1. Protecting information
  2. Limiting access to resources

This section describes these practices, and the practices established to ensure the continuity of service, access to it, and the payer's ability to interact with it.

Protecting information

The Tipalti Solution has the following main system components in addition to Tipalti's back-office system. Select a component below to reveal further information.

iFrame (iFrames) and APIs

The iFrame is served from web servers hosted with AWS and supported by a database cluster, also hosted with AWS. The databases are backed up automatically on a live basis; in other words, the databases are constantly replicated from Tipalti to an off-site location. The entire system image is backed up every day and once a week. The main servers are hosted by AWS.

Access to the iFrame and APIs is secured by:

  1. TLS - Ensures that information is protected in transit
  2. Payer web request authentication
    • All calls to the iFrame and APIs are authenticated with a cryptographic hash (SHA256 function) using a unique payer secret key.
    • The authenticating cryptographic hash contains a randomizing component so that repeat calls have different keys in effect.
  3. Support for key rotation
    • The authenticating cryptographic hash has a limited lifetime and expires if unused in the allotted time.
  4. Safelisting
    • All API calls (including calls to get a short-term key) can be safelisted.
    • Safelisting is optional and can be switched off, if desired by the payer.

      The default implementation for safelisting is "ON".

Action validation

Payee account activity (e.g., change in payment details, change in personal details, etc.) is logged automatically by Tipalti. The payer may choose to enable any of these actions:

  1. Changes are saved to the system only after the payee enters a validation code sent via email.
  2. Changes made by the payee are communicated automatically to the payer via:
    • Email
    • IPN
Tipalti Hub

All communication is protected via TLS secure transmit protocol.

  • Access to the Tipalti Hub is secured via 2FA, username and passwords. Passwords are required to be of a certain complexity and expire every 90 days.
  • Activity in the Tipalti Hub is restricted by user roles and only users with the Approve Payment role can authorize payments.
Database

Data

Sensitive data collected and stored (including account numbers, Social Security Numbers and other personally identifiable information) are encrypted with the AES. Tipalti uses the same level of encryption used by industry leaders, such as Amazon, eBay, PayPal, etc.

Access

  • Access to databases is restricted via Security Groups, a production domain role-based access controls, and network segmentation. Access to databases is given on a need-to basis and is strictly monitored for production databases and privileges.

Developers do not have access to production databases.

  • The databases are constantly replicated from Tipalti to an off-site location. The entire system image is backed up every day and once a week.

Limiting access to resources

To safeguard Tipalti's information, strict segregation exists between the "production" environment and all other systems. Select a system below to reveal further information.

Production information systems
  • Access to the production information systems is permitted only on a need-to basis to select staff, per case.
  • Access is restricted by:
    • Limiting the networks for which access is granted
    • Employing a separate domain for production systems
  • Any database or code upgrade to the production system is approved by the CEO, CTO or VP of Engineering.
  • The production servers and AWS account are monitored for errors, alerts and intrusion (intrusion detection system), in addition to other baseline security controls (Anti-Virus, Firewall, etc.).
Payment systems

Payment system interfaces are not hosted. The CEO and CTO maintain the systems and code for executing payments. In addition, the CEO, CTO and VP of Engineering have control of payment passwords and keys, which are not shared.

Blocked IPs

In addition to the security practices described above, Tipalti has blocked all IPs from the following locations:

  • Congo
  • Congo, Democratic Republic
  • Crimea
  • Cuba
  • Iran
  • North Korea
  • Sudan
  • South Sudan
  • Syria
  • Additional IP addresses are updated periodically in NCCT by regulators and authorities.

Payees and payer users in these locations see the following message when trying to access the iFrame and Tipalti Hub: "Tipalti service is not supported in the country from which you are attempting to access its service."

  • ZD.4.log-1212665864.zip
    20 KB Download
Was this article helpful?

We’d love the opportunity to improve. Submit your feedback.

We’re glad you enjoyed the article!

Have more questions? Submit a request
Return to top
Privacy Policy | Terms of Use | Payer/Sender Rights | Customer Assistance Policy
LinkedIn Instagram Facebook Twitter YouTube
Contact support