What's new in TrueChecks
This release adds multi-factor authentication (MFA) for TrueChecks portal users, improves alert logic for “Retired/Ineligible Routing Number” returns, and adds support for PGP-encrypted file uploads for SFTP contributions. These updates are live now.
- Multi-factor authentication (MFA): Admins can now require users to verify login with a text message, email, or authenticator app.
- Smarter “Retired/Ineligible Routing Number” alerts: Routing numbers are now checked against a daily Treasury registry before an alert is triggered.
- PGP-encrypted file uploads: Client admins can generate a PGP key pair to encrypt files submitted via SFTP
Multi-factor authentication (MFA) in TrueChecks Portal
Multi-Factor Authentication (MFA) can now be enabled for all TrueChecks portal users. Once enabled by your institution, users will be required to verify their login using a text message, email, or a third-party authenticator app (Google Authenticator, Microsoft Authenticator, etc.) in addition to their password.
MFA is disabled by default. Client admins can turn it on from the Password & Session screen under Administration, and can set how often users need to re-verify, anywhere from every login to every 30 days.
Once MFA is enabled, users will be prompted to choose a verification method the next time they log in and complete a short setup process. Users also receive one-time backup codes to use if their verification method is temporarily unavailable, and can manage their MFA settings (change verification method, reconfigure their authenticator app, or regenerate backup codes) from their profile page at any time.
This update is live now, but MFA is disabled by default. No action is required unless you'd like to enable it: admins can turn on MFA for their institution at any time from the Password & Session screen under Administration.
BENEFIT: An additional layer of security for TrueChecks portal access, helping institutions meet state, municipal, and regulatory requirements for multi-factor authentication.
Smarter alerts for “Retired/Ineligible Routing Number” returns
We've updated the logic behind “Retired/Ineligible Routing Number” alerts. When this type of return is received, TrueChecks now validates the routing number against a daily U.S. Treasury file of active, valid routing numbers.
If the routing number isn't found in the Treasury file, TrueChecks will recommend a Deny action. If the routing number is found, the “Retired/Ineligible Routing Number” alert will no longer trigger.
No action required. This update applies automatically.
BENEFIT: Reduces the risk of over-alerting on “Retired/Ineligible Routing Number” returns.
Accepting PGP-encrypted files for SFTP contributions
TrueChecks can now accept Pretty Good Privacy (PGP) encrypted files for SFTP contributions. Client admins can generate a PGP key pair from the SFTP Account page under TrueChecks Administration. The private key stays securely stored in TrueChecks, while the public key can be shared and used to encrypt files before upload.
Once a key pair is created, admins can copy the public key at any time, or regenerate the key pair if needed. Note: regenerating a key pair invalidates the old keys, so any file submissions using the old public key will need to be updated with the new one.
No action required unless you'd like to begin submitting encrypted files. Your admin can generate a key pair from the SFTP Account page at any time.
BENEFIT: A more secure way to transfer client data into TrueChecks for processing.
Comments
0 comments
Please sign in to leave a comment.