ACHPay Security Analysis

For online transactions using electronic checks, NIC Inc., uses a product they had developed in-house, names ACHPay. This product is used in many state portals. Due to the sensitive nature of information being dealt with during a payment transaction, NIC wanted to ensure that the ACHPay provides protects user’s sensitive information. 

SymSoft Solutions conducted a thorough security review of the ACHPay to identify and address application vulnerabilities for SQL injection, cross-site scripting etc. These enhancements addressed issues at multiple levels, including strengthening user authentication and authorization, filtering malicious requests and using encryption for storing sensitive information.

SymSoft worked with the central group within the NIC so that these updates are integrated in the products and are used by all the NIC portals.