Flip
Trust and compliance

Security engineered for the way money really moves

Customers entrust Flip with their own sensitive data and the personal details of the people they serve. As payments infrastructure, our security program is built for the bar the global financial industry sets — and we keep raising it alongside the industry itself.

Active certifications
01PCI DSS
02SOC 2 Type II
03ISO 27001
04SOC 1
05PCI Service Provider Level 1
§ 02 · Standards

Independently audited against every framework that counts

Third-party assessors evaluate Flip on a published schedule against the most demanding frameworks in payments, financial services, and privacy.

01

PCI Service Provider Level 1

An accredited PCI auditor takes Flip through a full external assessment each year and certifies us to PCI Service Provider Level 1 — the strictest tier the card networks issue. The audit reviews both our Card Data Vault (CDV) and the secure-development pipeline behind our integration code. Inside the Dashboard, we generate the right PCI validation form for your integration, walk you through a Self-Assessment Questionnaire when you're on Elements, Checkout, Terminal SDKs, or our mobile libraries, and publish a companion PCI Compliance Guide.

PCI DSSPCI Service Provider Level 1
02

System and Organization Controls (SOC) reports

Each year, an independent auditor reviews Flip's systems, processes, and controls under our SOC 1 and SOC 2 programs. SOC 1 Type II and SOC 2 Type II reports go out under NDA on request. Our SOC 3 — written to the AICPA Trust Service Criteria — is a public summary of the controls protecting security, availability, and confidentiality.

SOC 1 Type IISOC 2 Type IISOC 3
03

EMVCo standard for card terminals

Flip Terminal carries EMVCo Level 1 and Level 2 certification for chip-card security and interoperability, and is validated against PCI PA-DSS — the global benchmark that keeps third-party payment apps from holding onto prohibited cardholder data.

EMVCo L1EMVCo L2PA-DSS
04

NIST Cybersecurity Framework

Flip's information security program — policies, controls, and the way they're designed — maps to the NIST Cybersecurity Framework. That alignment is what large enterprise customers rely on when they're certifying their own cloud-computing and storage products.

05

Privacy and data protection

Flip's privacy practices are certified under the CBPR and PRP systems, and we operate in compliance with the EU-US Data Privacy Framework (DPF), its UK Extension, and the Swiss-US Data Privacy Framework.

CBPRPRPEU-US DPFUK ExtensionSwiss-US DPF
§ 03 · Product

Defenses built into the product

Controls that ship inside Flip — protecting your account, your team, and the customers you serve, from day one.

Authentication for sensitive actions

The Flip Dashboard ships every modern factor of multi-factor authentication: passkeys (recommended — phishing-resistant), hardware security keys (recommended — phishing-resistant), TOTP, and SMS (not recommended — vulnerable to SIM-swap and intercept). For teams, we ship SAML 2.0 SSO, mandatory sign-in enforcement, granular role-based access, just-in-time (JIT) provisioning, and SCIM with your identity provider. Support requests are gated on Dashboard sign-in or out-of-band account verification — no exceptions.

Access controls and audit logs

Set granular roles from the Dashboard to keep every team member on least-privilege by default. Issue restricted API keys, pin secret keys to specific IP ranges, and review the security history log for sensitive actions — with device and IP fingerprinting and failed sign-in attempts surfaced inline. Flip emails you the moment a login arrives from an unknown device or IP, and full history exports on demand.

HTTPS and HSTS by default

Every Flip service is HTTPS-only over TLS. We continuously audit certificates, certificate authorities, and cipher suites, enforce HSTS, ship HSTS preload in every major browser, and refuse TLS versions below 1.2. Internal server-to-server traffic is wrapped in mutual TLS (mTLS), and the team uses dedicated PGP keys for encrypted email. flip.com sits on Chrome's top-domain list, with active monitoring for homoglyph spoofing.

Always-on internet monitoring

We continuously sweep the open web for leaked merchant API keys, plug into the GitHub Token Scanner to alert you when keys land in public repos, hunt phishing pages impersonating Flip, file takedowns, and submit findings to Google Safe Browsing.

§ 04 · Infrastructure

A hardened, continuously tested infrastructure

Our team probes the infrastructure non-stop — automated scans, quarterly penetration tests, and external red-team exercises with top-tier firms. Findings are triaged and shipped to fix on the same day. Servers retire on a fixed schedule to stay healthy and flush stale state, and we upgrade OSes well ahead of end-of-life cutoffs.

Layer

Purpose-built card infrastructure

Flip encrypts sensitive data in flight and at rest, full stop. The systems that store, decrypt, and transmit primary account numbers (PANs) run as a fully separate environment from the rest of Flip — no shared credentials with our main API or marketing site. The Card Data Vault (CDV) sits in its own AWS account, reachable to a small set of specially trained engineers whose access we review every quarter. PANs are encrypted at rest with AES-256, decryption keys live on separate hardware, and PANs are tokenized internally so no plain-text card number ever reaches an application server or daemon. A static allowlist explicitly governs which downstream providers can receive card transmissions, and bank account numbers are tokenized exactly the same way.

Layer

Corporate technology under zero trust

Employee access at Flip operates on zero-trust principles. Every employee signs in with SSO, a hardware-token 2FA, and mTLS via cryptographic certificates issued to Flip-managed machines. Sensitive systems demand additional privileges that go beyond an employee's day-to-day scope. We watch audit logs for anomalies, run intrusion detection on suspicious activity, alert on sensitive file changes, and require multi-party code review with automated testing for every change. The code-change log is immutable and tamper-evident. Flip-issued laptops run continuous endpoint monitoring against malicious processes, fraudulent domains, and intrusion attempts, and a software allowlist stops unapproved binaries from ever launching.

§ 05 · Posture

The practices that keep our posture honest

Security engineers join product teams at the kickoff of every project. The Security Review process produces threat models and trust boundaries that anchor the implementation — and gate every future change to sensitive code.

Always-on security experts

Dedicated teams cover infrastructure, operations, privacy, users, and applications — backed by a 24/7 on-call rotation so a specialist is always reachable.

Security is everyone's job at Flip

Every employee completes annual security training. Engineers add secure-software-development coursework on top. Internal phishing exercises keep recognition and reporting reflexes sharp year-round.

Managing access at scale

We formalize access grants, run periodic access reviews, auto-revoke dormant access, and require human sign-off on sensitive infrastructure. Least-privilege is the default, and we retain only the data we need to meet regulatory and business obligations.

Vulnerability disclosure and rewards

We run a public vulnerability disclosure and reward (bug bounty) program that pays independent researchers for valid findings. Submissions go through HackerOne under our published program rules.

§ 07 · Register

Certifications, on the record

Certification
Type
Status
PCI Service Provider Level 1
Payment Card Industry
Active
SOC 1 Type II
System Controls
Annual
SOC 2 Type II
System Controls
Annual
SOC 3
System Controls
Publicly available
EMVCo Level 1 & 2
Card Terminal
Active
PA-DSS
Payment Application
Active
NIST Cybersecurity Framework
Cybersecurity
Aligned
CBPR
Privacy
Active
PRP
Privacy
Active
EU-US Data Privacy Framework
Data Protection
Active
UK Extension (EU-US DPF)
Data Protection
Active
Swiss-US Data Privacy Framework
Data Protection
Active
§ 08 · Build

Build on infrastructure your auditors can verify

Browse the Trust Center for the complete picture, pull SOC reports under NDA, or set up a working session with our compliance team.