Security Overview
Last updated October 9, 2026
Summary
TriMatch handles invoices, vendor bank details and payment files, so we treat security as part of the product. This page is a short overview. It does not mean TriMatch holds SOC 2, PCI, HIPAA or any other certification.
Protecting data
- All traffic uses HTTPS. Secrets are kept in the host's secret store, never in source code.
- Sensitive fields, such as tax IDs and bank details, and uploaded documents are encrypted at rest, with a separate encryption key for each company. Normal screens show masked values.
- Each company's data is kept separate. Access to another company is only possible through an explicitly linked identity; a matching email address is never enough.
- Complete backups are encrypted and stored offsite (Backblaze B2, United States), with a documented restore procedure.
- TriMatch never holds or moves money. It prepares bank payment files that your bank processes.
Sign-in and access
- Two-factor sign-in with an authenticator app, and admins can require it for everyone in their company.
- Passwords are stored only as strong one-way hashes. Repeated failed sign-ins lock the account for a while, and sign-up is protected against bots.
- Roles and permissions limit who can approve, pay or change bank details. Team members can be limited to locations and departments.
Payment fraud controls
- A change to a vendor's bank details only takes effect after someone confirms it by calling a phone number already on record.
- Bank files stay locked until bank acceptance has been recorded.
- Vendors are screened against the US Treasury sanctions list.
Audit trail and monitoring
- Every change and every access to sensitive records is written to an append-only, tamper-evident audit trail. A daily fingerprint of each trail is stored offsite.
- We monitor failed jobs and messages, backups, disk space and integration errors, and respond to alerts.
Reporting a vulnerability
Please report suspected security issues privately to security@trimatchap.com. Do not include bank numbers, tax IDs, passwords, tokens or invoice documents in ordinary email. Please give us reasonable time to fix an issue before telling anyone else, and do not access other customers' data or disrupt the service while testing.