Access and Security

Prev Next

Platform Overview

Ripple Treasury is a web-based cloud application, with a multi-tiered architecture using firewalls and physically-segregated layers. The application uses a Software as a Service (SaaS) model hosted at secure global data centers. Ripple Treasury has partnered with Microsoft Azure to protect your data with the industry’s strongest security and compliance standards.

The Ripple Treasury system is accessible via a secure, modern web browser (Microsoft Internet Explorer 11, Microsoft Edge, or Chrome). Clients have full control over all access to the application, including access by Ripple Treasury Support. Support can access the live production environment only if a ticket has been opened by the client. All-access to the application is logged and regularly reviewed by the Ripple Treasury Compliance department.

Encryption

The use of encryption is limited to those algorithms that have received substantial public review and have been proven to work effectively.

The type of encryption used depends on the context:

  • Communication over the Internet uses 2048-bit Secure Socket Layer (SSL) over Transport Layer Security (TLS) 1.2.

  • Certificates use a minimum key length of 256 bits.

  • Secure Shell (SSH) keys are 2048-bit RSA and are stored in a secured area of the Ripple Treasury file server, with access governed by senior management.

  • Pretty Good Privacy (PGP) keys are 2048-bit RSA.

  • Cryptography keys apply to all cardholder data and are generated by DevOps. Keys, including SSL, PGP, and SSH assets are stored in designated secure repositories.

Certification

When choosing a TMS, it is important to know whether the vendor and application are compliant with the latest industry-approved security standards. These standards are critical in protecting customer data. Ripple Treasury complies with the following security standards:

  • Service Organization Controls (SOC): We comply with SOC 1 Type 2 (financial controls) and SOC 2 Type 2 (data security) annually. Whereas SOC 1 focuses primarily on financial controls and reporting (to mitigate risk and protect against fraud), the SOC 2 report is more security-oriented and focuses on principles of security and availability.

  • Payment Card Industry – Data Security Standards (PCI-DSS): PCI-DSS is related to the handling of credit card information. PCI is a series of methodologies and best practices used to secure payment card data from security breaches. All servers and related hardware through which sensitive client data may pass are certified for PCI compliance, including our internal network and production data centers.

  • Society for Worldwide Interbank Financial Telecommunication (SWIFT): Ripple Treasury has been a member of the SWIFT organization for years, and we are also a Certified Member for Corporate Cash Management. We were one of the first members to provide SWIFT AL2 connectivity as an option for bank communication and are required to undergo an audit every three years to ensure we are compliant with their data security standards.

  • Penetration Tests: Testing by a third-party auditing firm is conducted annually against the internal and external networks as well as the Ripple Treasury application.

  • Vulnerability Scans: Quarterly vulnerability scanning is conducted by a third-party auditing firm.

  • Code Scans and Other Test Types: The Ripple Treasury application is developed using secure coding techniques and protected with ongoing code reviews along with nightly static code scans. On an ongoing basis, servers are tested against public Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) databases.

Application Access and Logins 

Access to the Ripple Treasury application is secured by strong password standards. Initial passwords must be changed after login and may not contain parts of the user’s account name, full name, numbers associated with personal information, or common words. Commonly-used sequences or repetition of the same character is also prohibited. Passwords must contain at least fourteen (14) characters in length and meet industry-standard complexity requirements. Passwords expire after 30 days, and the previous eight (6) passwords may not be re-used. Password standards are subject to change at any time based on the latest security standards.

In addition to default settings, Ripple Treasury can be configured to comply with any client standards as well.

The most critical component of application security is the login process, as login security is the gateway to the application. Ripple Treasury provides several standard and optional ways of ensuring only authorized users are allowed in. While individual login features are important, you need a suite of features to ensure the highest level of security surrounding the application.

Ripple Treasury fortifies logins with the following features:

  • Single Sign-On (SSO): Single Sign-On allows you to log in to the application and related system using established credentials via the SAML 2.0 standard protocol. SSO increases security by requiring fewer logins and storing data in fewer locations in the system.

  • Multi-Factor Authentication (MFA): MFA provides an additional level of security over logins by requiring an additional piece of information unique to the individual. In addition to logins, MFA can also be used for payment approvals. For example, when sending high-value payments over a certain amount, you can require one or more approvers to authenticate via MFA before approving the payment.

Ripple Treasury provides two options for multi-factor authentication:

o RSA SecurID: A well-known method using a physical token method providing a unique, temporary security code required to access the application.

o Symantec VIP: Instead of a physical token, this method uses a secure application on your mobile device or computer to generate a temporary code.

  • IP White Listing: Allows you to specify the addresses allowed to access the Ripple Treasury application. For organizations concerned about the locations from which users are accessing the application, IP whitelisting is a great option. Even better, this option can be combined with SSO to provide an even greater level of security.

User Views

Ripple Treasury uses a tabbed interface depending on the modules chosen by the client. After successfully logging in, users can only see the tabs and features to which they have been granted access.

Access Groups and Permissions

The Ripple Treasury application uses a multi-level group model for assigning permissions to the features and modules. Usually, top-level groups are created by role or function, and sub-groups are created for access to specific modules. Access to functions within those modules (view, add, edit, etc.) is then configured using checkboxes.

Most of the system is configurable, from individual modules to payment instrument types, bank accounts, approval permission, approval amounts, and much more. Access can be as restrictive or as general as management requires and touches all parts of the application as well as functionality in the system. Users can be deactivated and transferred between different permission groups.

Auditing

Audit reports may be generated using our full-featured reporting tools. Additionally, every action and transaction is logged. Audit trails are provided in two forms: First, each record is marked with control stamps associated with every step in the process. Control stamps record the operator ID, the action taken, the date and time and the additional comments/description if applicable. Second, more traditional audit trails record activities in a table and/or flat file in sequence as they occur. Data elements vary with the type of activity, but generally, they include the unique transaction number and a before and after picture of the activity.

Definitions and Acronyms

Access & Security Knowledge Note - Definitions table.png