Skip to content

Security Settings

Security Settings help you protect your agency's GovPayPlan account and maintain compliance with security requirements.

Accessing Security Settings

  1. Navigate to Settings > Security
  2. Administrator role required

Multi-Factor Authentication (MFA)

What is MFA?

MFA adds an extra layer of security by requiring a second form of verification beyond the password.

Supported MFA Methods

  • Authenticator App (Recommended): Google Authenticator, Authy, etc.
  • SMS: Text message codes
  • Email: Email verification codes

Enabling MFA for Your Agency

  1. Navigate to Settings > Security > MFA
  2. Toggle Require MFA to On
  3. Select allowed MFA methods
  4. Set grace period for users to enroll
  5. Save

MFA Policies

PolicyDescription
Required for all usersAll users must enable MFA
Required for admins onlyOnly admin roles require MFA
OptionalUsers can choose to enable MFA

User MFA Enrollment

When MFA is required:

  1. User logs in and is prompted to enroll
  2. User selects their MFA method
  3. User completes verification setup
  4. MFA is active for future logins

Password Policies

Configurable Requirements

SettingOptions
Minimum length8-32 characters
Require uppercaseYes/No
Require lowercaseYes/No
Require numbersYes/No
Require special charactersYes/No
Password historyPrevent reuse of last N passwords
Maximum ageDays before password must change

Setting Password Policy

  1. Navigate to Security > Password Policy
  2. Configure requirements
  3. Save changes

TIP

Stronger password policies improve security but may increase support requests. Balance security with usability.

Session Management

Session Timeout

Configure automatic logout after inactivity:

  • 15 minutes (high security)
  • 30 minutes (recommended)
  • 60 minutes (standard)
  • Custom duration

Concurrent Sessions

Control multiple logins:

  • Allow unlimited sessions
  • Limit to N sessions per user
  • Single session only (logout previous on new login)

Session Settings

  1. Navigate to Security > Sessions
  2. Set timeout duration
  3. Configure concurrent session policy
  4. Save

IP Restrictions

IP Allowlist

Restrict access to specific IP addresses:

  1. Navigate to Security > IP Restrictions
  2. Click Add IP Address
  3. Enter IP or CIDR range
  4. Add description
  5. Enable allowlist

Managing IP Restrictions

ActionHow
Add IPEnter IP and description
Remove IPClick delete next to IP
Disable temporarilyToggle allowlist off

WARNING

Be careful with IP restrictions. Incorrect configuration can lock out legitimate users.

Login Security

Failed Login Lockout

Configure account lockout after failed attempts:

  • Number of attempts before lockout
  • Lockout duration
  • Notification on lockout

CAPTCHA

Enable CAPTCHA for login:

  • After N failed attempts
  • Always required
  • Disabled

Audit Logging

What's Logged

GovPayPlan automatically logs:

  • User logins and logouts
  • Failed login attempts
  • Password changes
  • Permission changes
  • Configuration changes
  • Payment transactions
  • Refund actions

Viewing Audit Logs

  1. Navigate to Security > Audit Log
  2. Filter by:
    • Date range
    • User
    • Action type
  3. Export as needed

Audit Log Retention

Configure how long logs are retained:

  • 90 days (minimum)
  • 1 year (recommended)
  • 7 years (compliance)
  • Custom

Compliance

PCI-DSS

GovPayPlan is PCI-DSS compliant. Your responsibilities:

  • Protect user credentials
  • Maintain access controls
  • Monitor for suspicious activity
  • Report security incidents

Security Certifications

GovPayPlan maintains:

  • PCI-DSS Level 1
  • SOC 2 Type II
  • Regular penetration testing

Security Best Practices

  1. Enable MFA for all users
  2. Use strong passwords with complexity requirements
  3. Review access regularly
  4. Monitor audit logs for suspicious activity
  5. Keep contact info current for security notifications
  6. Train users on security awareness

Incident Response

Reporting Security Issues

If you suspect a security issue:

  1. Contact your agency administrator immediately
  2. Document what you observed
  3. Do not attempt to investigate yourself
  4. Contact GovPayPlan support

Emergency Actions

Administrators can:

  • Disable all user accounts
  • Revoke API keys
  • Enable emergency MFA requirement
  • Lock down IP access

GovPayPlan - Secure Payment Processing for Government Agencies