Multi-Factor Authentication (MFA) Policy
Critical Security Requirement
MFA is mandatory for all admin-level accounts. Any account without MFA enabled is a compliance violation and must be remediated immediately.
Company: Payzario Inc. | Effective Date: April 2025 | Version: 1.0
1. Purpose
This policy requires Multi-Factor Authentication (MFA) on all administrative and privileged accounts across every platform Payzario uses. MFA is a non-negotiable security control that significantly reduces the risk of unauthorized access, credential theft, and account takeover.
2. Scope
This policy applies to all Payzario founders, employees, contractors, and vendors with admin or privileged access to any of the systems listed below. No exceptions.
3. Required MFA — Platform by Platform
Base44 (App Platform / Admin Login)
- MFA must be enabled on the Base44 account used to manage the Payzario app.
- Admin-role accounts within the app must use strong, unique passwords.
- No shared admin accounts — each admin must have a unique login.
- Status: Enable via Base44 dashboard → Settings → Security.
Google Workspace / Gmail
- MFA is mandatory on all Google accounts associated with Payzario (e.g., support@payzario.com, admin@payzario.com).
- Use Google Authenticator, a hardware key, or passkeys — not SMS where avoidable.
- Enforce MFA org-wide via Google Admin Console if using Google Workspace.
- Status: Enable via myaccount.google.com → Security → 2-Step Verification.
Stripe
- MFA must be enabled on all Stripe team member accounts.
- Restricted API keys should be used where possible — avoid using secret keys directly.
- Immediately rotate keys if a team member with access leaves.
- Status: Enable via Stripe Dashboard → Profile → Two-step authentication.
Plaid
- MFA must be enabled on the Plaid developer dashboard account.
- Plaid API keys (client ID and secret) must be stored only in secure environment variables — never in code or shared via chat/email.
- Access to the Plaid dashboard must be limited to the minimum number of authorized individuals.
- Status: Enable via Plaid Dashboard → Account Settings → Security.
Domain Registrar & Hosting Account
- MFA must be enabled on the account controlling payzario.com's domain registration.
- MFA must be enabled on any cloud hosting, DNS, or CDN provider account (e.g., GoDaddy, Namecheap, Cloudflare, AWS, etc.).
- Recovery codes must be stored securely offline — not in email or unencrypted notes.
- Access must be limited to the founding team only.
Any Admin Dashboard or Internal Tool
- Any tool with access to customer data, financial records, or system configuration must require MFA for admin access.
- This includes internal dashboards, analytics tools, support portals, and monitoring services.
- If MFA is not natively supported by a tool, access must be gated behind a VPN or IP allowlist as a compensating control.
4. Acceptable MFA Methods (in order of preference)
- Hardware security key (e.g., YubiKey) — strongest
- Authenticator app (e.g., Google Authenticator, Authy, 1Password)
- Passkeys / biometric authentication
- SMS-based OTP — acceptable but least preferred due to SIM-swap risk
5. Enforcement & Verification
- MFA status must be verified for every account during the monthly access review.
- Any account found without MFA must have it enabled within 24 hours of discovery.
- Accounts that cannot have MFA enabled must be escalated and mitigated with a compensating control.
- Findings and remediation actions must be logged in the monthly access review record.
6. Incident Response
If an admin account is suspected of being compromised:
- Immediately revoke access and reset credentials.
- Rotate all API keys associated with the compromised account.
- Enable or re-enroll MFA before restoring access.
- Document the incident and report to support@payzario.com within 24 hours.
7. Policy Review
This policy is reviewed annually or immediately following any security incident involving account compromise.
Owner: Payzario Inc. | Contact: support@payzario.com