Flip
Trust and compliance

How Flip protects your money and your data

Customers count on Flip to safeguard their own data and the personal information of the people they serve. As a payments infrastructure company, our security program is built to hold up to the toughest standards the global financial industry can throw at it — and keeps moving forward as those standards do.

Live certifications
PCI DSS
SOC 2 Type II
ISO 27001
SOC 1
PCI Service Provider Level 1

Audited against the standards that matter

External assessors review Flip every year against the highest-stakes frameworks in payments, financial services, and data protection.

PCI Service Provider Level 1

A PCI-certified auditor put Flip through a full external assessment and certified us to PCI Service Provider Level 1 — the highest tier the card networks recognize. The audit reviews both our Card Data Vault (CDV) and the secure-development process behind our integration code. Inside the Dashboard, we tailor your PCI validation form to your integration path, help you complete a Self-Assessment Questionnaire when you're on Elements, Checkout, Terminal SDKs, or our mobile libraries, and ship a PCI Compliance Guide alongside.

PCI DSSPCI Service Provider Level 1

System and Organization Controls (SOC) reports

Every year, an independent auditor evaluates our systems, processes, and controls under our SOC 1 and SOC 2 programs. We make SOC 1 Type II and SOC 2 Type II reports available under NDA on request. Our SOC 3, written against the AICPA Trust Service Criteria, is a public-facing summary of the controls protecting security, availability, and confidentiality.

SOC 1 Type IISOC 2 Type IISOC 3

EMVCo standard for card terminals

Flip Terminal carries EMVCo Level 1 and Level 2 certification for chip-card security and interoperability, and is validated against PCI PA-DSS — the global benchmark that keeps third-party payment apps from holding onto prohibited cardholder data.

EMVCo L1EMVCo L2PA-DSS

NIST Cybersecurity Framework

Flip's information security program — policies, controls, and the way they're designed — maps to the NIST Cybersecurity Framework. That alignment is what large enterprise customers rely on when they're certifying their own cloud-computing and storage products.

Privacy and data protection

Flip's privacy practices are certified under the CBPR and PRP systems, and we operate in compliance with the EU-US Data Privacy Framework (DPF), its UK Extension, and the Swiss-US Data Privacy Framework.

CBPRPRPEU-US DPFUK ExtensionSwiss-US DPF

Product security inside Flip

Controls that ship with the product to defend your account, your team, and the customers you serve.

Authentication for sensitive actions

The Flip Dashboard supports several layers of multi-factor authentication: passkeys (recommended — phishing-resistant), hardware security keys (recommended — phishing-resistant), TOTP, and SMS (not recommended — vulnerable to SIM-swap and intercept). For teams, we ship SAML 2.0 SSO, mandatory sign-in policies, fine-grained role-based access, just-in-time (JIT) provisioning, and SCIM with your identity provider. Every support request is gated on Dashboard sign-in or out-of-band account verification.

Access controls and audit logs

Define granular roles to keep every team member on least-privilege from the Dashboard. Mint restricted API keys, pin secret keys to specific IP ranges, and walk through the security history log for sensitive activity — including device and IP fingerprinting and failed sign-in attempts. Flip notifies you by email when a login arrives from an unknown device or IP, and you can export full history on demand.

HTTPS and HSTS by default

Every Flip service is HTTPS-only over TLS. We continuously audit certificates, certificate authorities, and cipher suites, enforce HSTS, ship HSTS preload in every major browser, and refuse TLS versions below 1.2. Internal server-to-server traffic is wrapped in mutual TLS (mTLS), and the team uses dedicated PGP keys for encrypted email. flip.com sits on Chrome's top-domain list, with active monitoring for homoglyph spoofing.

Always-on internet monitoring

We continuously sweep the open web for leaked merchant API keys, plug into the GitHub Token Scanner to alert you when keys land in public repos, hunt phishing pages impersonating Flip, file takedowns, and submit findings to Google Safe Browsing.

Hardening the infrastructure

Our security organization tests the infrastructure constantly — automated vulnerability scans, scheduled penetration tests, and red-team exercises run by leading external firms. Findings are triaged and addressed immediately. Servers cycle out on a regular cadence to stay healthy and shed stale state, and operating systems are upgraded well before end-of-life.

Purpose-built card infrastructure

Flip encrypts every byte of sensitive data both in flight and at rest. The systems that store, decrypt, and transmit primary account numbers (PANs) run as a separate environment from the rest of Flip, with no shared credentials with our main API or website. The Card Data Vault (CDV) sits in its own AWS account, reachable only to a handful of specially trained engineers whose access we review every quarter. PANs are encrypted with AES-256 at rest, decryption keys live on separate hardware, and PANs are tokenized internally — no plain-text card number is ever in reach of an application server or daemon. An explicit static allowlist gates which downstream providers can receive card transmissions, and bank account numbers are tokenized in exactly the same way.

Corporate technology under zero trust

Employee access at Flip operates on zero-trust principles. Every employee signs in with SSO, a hardware-token 2FA, and mTLS via cryptographic certificates issued to Flip-managed machines. Sensitive systems demand additional privileges that go beyond an employee's day-to-day scope. We watch audit logs for anomalies, run intrusion detection on suspicious activity, alert on sensitive file changes, and require multi-party code review with automated testing for every change. The code-change log is immutable and tamper-evident. Flip-issued laptops run continuous endpoint monitoring against malicious processes, fraudulent domains, and intrusion attempts, and a software allowlist stops unapproved binaries from ever launching.

Keeping our security posture sharp

Security engineers are embedded with product teams from the start of every project. The Security Review process produces threat models and trust boundaries that frame the implementation — and gate any future change to sensitive code.

Always-on security experts

Specialized teams cover infrastructure, operations, privacy, users, and applications — with a 24/7 on-call rotation so somebody is always paged in.

Security is everyone's job at Flip

All employees complete annual security training. Engineers also complete secure-software-development coursework. Internal phishing campaigns keep recognition and reporting sharp.

Managing access at scale

We formalize access grants, run periodic access reviews, auto-revoke dormant access, and require human sign-off on sensitive infrastructure. Least-privilege is the default, and we retain only the data we need to meet regulatory and business obligations.

Vulnerability disclosure and rewards

We run a public vulnerability disclosure and reward (bug bounty) program that pays independent researchers for valid findings. Submissions go through HackerOne under our published program rules.

The certification register

CertificationTypeStatus
PCI Service Provider Level 1Payment Card IndustryActive
SOC 1 Type IISystem ControlsAnnual
SOC 2 Type IISystem ControlsAnnual
SOC 3System ControlsPublicly available
EMVCo Level 1 & 2Card TerminalActive
PA-DSSPayment ApplicationActive
NIST Cybersecurity FrameworkCybersecurityAligned
CBPRPrivacyActive
PRPPrivacyActive
EU-US Data Privacy FrameworkData ProtectionActive
UK Extension (EU-US DPF)Data ProtectionActive
Swiss-US Data Privacy FrameworkData ProtectionActive

Run on infrastructure you can verify

Visit our Trust Center for the full picture, request SOC reports, or get our compliance team on a call.