Legal CenterAugust 21, 2026

Security Policy

  1. Scope. As described in this Security Policy, Modern Treasury uses commercially reasonable technical and organizational measures designed to prevent unauthorized access, use, alteration, or disclosure of Customer Data stored on Modern Treasury systems. This Security Policy applies to Modern Treasury systems and personnel. The Products include security options that Customer may use (see Section 5 below), and Customer is responsible for its own configurations and the security of its own systems. While certain Products may enable Customer to connect with its accounts at Banks or other Third-Party Platforms, Modern Treasury does not control and is not responsible how such third parties secure or process data.
  2. Encryption & Customer Data.
    1. Modern Treasury secures all Customer Data using industry-standard TLS 1.3 for transmissions and AES 256-bit encryption for all data stored at rest within our Product production environment.
    2. Modern Treasury logically separates Customer Data from that of other customers and uses measures designed to prevent Customer Data from being exposed to other customers.
  3. Asset Management. Modern Treasury requires all company-owned endpoint assets to be secured with full-disk encryption and monitored by Endpoint Detection and Response (EDR) solutions. Furthermore, our policies strictly prohibit the storage of Customer Data on removable electronic storage devices, such as thumb drives, to prevent unauthorized data exposure.
  4. Access Controls.
    1. Systems access by Modern Treasury personnel is determined on a need-to-use basis, as defined based on the responsibilities and duties of the position held.
    2. Modern Treasury requires personnel to use unique user IDs, complex passwords and multi-factor authentication to access Product production environments.
  5. Application Security & Customer Controls.
    1. The Products allow Customer to use multi-factor authentication as described in the Documentation.
    2. In addition, the Products allow Customer to manage its User permissioning, determine payment approval rules (for the Payment Products) and access and export audit trails, subject to the plan features available under Customer’s Order.
    3. Customer may export its Customer Data through the standard functionality of the Products.
  6. Network Security, Environmental & Physical Controls.
    1. The Products operate on Amazon Web Services (“AWS”) and are protected by security and environment controls of AWS. Information regarding AWS security is available at https://aws.amazon.com/security/.
    2. Modern Treasury’s physical offices maintain security surveillance and visitor access restrictions.
  7. Personnel Management.
    1. Modern Treasury requires background checks of all personnel with access to Customer Data.
    2. All Modern Treasury personnel undergo annual security awareness training. Modern Treasury personnel in developer roles undergo annual secure coding training.
    3. Modern Treasury immediately disables physical and logical access to Modern Treasury resources upon personnel termination.
  8. Organizational Policies. Modern Treasury maintains and regularly reviews internal organizational policies, including a Data Management Policy, Cryptography Policy, Information Security Policy, Risk Management Policy, Access Control Policy and Vulnerability Management Policy.
  9. Business Continuity & Disaster Recovery
    1. Modern Treasury maintains a Business Continuity Plan (“BCP”) and Disaster Recovery Plan (“DRP”) to govern contingency plans for certain business interruptions and disasters affecting its business and Products.
    2. Modern Treasury tests the BCP and DRP annually.
  10. Security Assessments
    1. Modern Treasury engages a third-party auditor to conduct an annual SOC 1 Type II and SOC 2 Type II (or similar or successor) reports (“SOC Reports”). Modern Treasury engages a third party to conduct annual vulnerability assessments and reports (“Vulnerability Reports”). SOC Reports and summary Vulnerability Reports are available to Customer on annual request, subject to confidentiality terms.
    2. In addition, Modern Treasury performs ongoing internal vulnerability scanning and regular external vulnerability scanning.
  11. Incident Response. Modern Treasury maintains an Incident Response Plan (“IRP”) to respond to potential security incidents, malware infection or intrusions to the Products or Customer Data, based on severity of impact.
  12. Security Breach. If Modern Treasury becomes aware of unauthorized access to or disclosure of personal information in Customer Data due to a breach of Modern Treasury's security (“Security Breach”), then unless limited by Laws, Modern Treasury will notify Customer of the Security Breach within three (3) business days of confirmation and provide Customer with information about when and where the Security Breach may have occurred, the effect on Customer Data and Modern Treasury’s corrective action in response to the Security Breach.

This version of the Security Policy applies to Orders entered into on or after August 21, 2026. For Customers who entered into an Order prior to August 21, 2026, this version of the Security Policy will apply upon your next renewal.

Get legal updates

Subscribe via the RSS feed or email for notifications whenever a legal update is published.