At Ramp, we take security and protection of your data very seriously. We achieve this goal through a multitude of approaches:
All data is transmitted with encryption-in-transit using HTTPS or similar protocols. Furthermore, all data is securely stored with encryption-at-rest using AES-256 or higher standards. Where possible within databases, we also leverage in-field encryption to protect particularly sensitive data.
Least Privileges and Audit Logging
As standard best practice, we adhere to the notion of least privileges, whereby only a small subset of personnel have the means to view your data, and only when needed to support you. Naturally, all data access is logged and monitored for audit purposes too.
Ramp continuously undergoes automated penetration testing to check for any vulnerabilities in our infrastructure. The tests are augmented by manual "business logic assessment" reviews on a periodic cadence.
On an annual basis, Ramp is audited by a large external firm to ensure we continue to meet and exceed the requirements of SOC 2, a compliance standard. We ensure that all of our partners have current SOC 2 reports too.
Above and beyond multi-factor authentication on your account, Ramp leverages automated systems to proactively prevent account takeover attempts and other malicious requests. We also support SSO through your identity provider (i.e. Google or Okta) and immediately verify suspicious activity with the business owner.
WAF and DDoS Protection
Ramp uses an industry leading firewall provider to protect against distributed denial-of-service (DDoS) attacks and attempted intrusions into our systems. We also block certain countries and enforce rate limiting to prevent against brute-force attacks.
Trusted Third Parties
When we need to leverage third-parties to help provide service to you (i.e. with bank account linking, leveraging Finicity and Teller), we verify that they have adopted equally stringent security protocols. Our legal officer ensures we have a comprehensive contract in place and our security team further approves any engagement.