Security and data protection
This page describes, per bank connection, how 365 business Banking protects credentials, keys and account data, and lists the endpoints for your firewall.
Credentials and passwords
| Data | Storage location | Visibility |
|---|---|---|
| Online banking credentials (PSD2/XS2A) | Not stored in Business Central. You enter them only in your bank's web form. | only you, at your bank |
| Bank access password (company bank access, personal bank access) | generated randomly by Business Central from a cryptographically secure source and kept in the app's isolated storage, additionally encrypted if encryption is enabled | does not have to be entered; shown only on the Technical details FastTab, which only users with the SUPER or 365 Banking - Setup permission set see |
| EBICS keys | The key pair is created by the EBICS service. The private key is stored encrypted with your key password on the EBICS participant in Business Central. | nobody in plain text; without the key password it cannot be used |
| Key password (EBICS) | in the app's isolated storage, additionally encrypted if encryption is enabled. | nobody; it can only be set again, not displayed |
| Payment service provider credentials (API key, client secret, token) | as a field on the provider's connection setup, that is, in a Business Central table and not in isolated storage; the exception is the Amazon Pay private key, which is kept in the app's isolated storage, additionally encrypted if encryption is enabled | masked on the page, including Klarna; however, users with read access to the setup table can read the values |
| Files (camt, pain, Universal) | no credentials required | not applicable |
Storing the other payment service provider credentials in isolated storage is planned for version 18.5. Until then, give read access to the payment service provider setups only to people who need it.
Grant payment service providers only the required rights
Where the provider offers it, use a restricted key with exactly the permissions that 365 business Banking requires, for example a restricted key at Stripe. The required rights are listed on the page of each payment service provider.
Bank connection
PSD2/XS2A via finAPI
The connection to your bank is established by finAPI GmbH, a BaFin-licensed account information service (AIS) and payment initiation service (PIS). You sign in to your bank directly in the web form and confirm access with a TAN. You also approve every payment there. Business Central has no access to your credentials. Under PSD2, the consent you give your bank expires regularly and must be renewed. See Renew consent.
EBICS
Business Central does not communicate with your bank directly but through the EBICS service of the 365 business API, which forwards the orders to your participant's bank URL. The service is stateless: Business Central stores the participant's state, including the encrypted private key, and sends it with every request, together with the key password, over an encrypted connection. Your bank activates the participant only after receiving your signed initialization letter, and the hash values of the bank keys are checked before first use.
camt/pain file
Business Central does not communicate with any bank. Every file is transferred manually, and your bank requires its usual approval when you upload a payment file.
Payment service providers
Business Central calls the provider's interface directly with the stored credentials. For Mollie and Shopify, you authorize Business Central on the provider's sign-in page; no password is stored in Business Central.
Who may see and do what
- Banking (Base) grants access to all functions for daily work with 365 business Banking. The setups can be read with it but not changed on the setup pages. Assign this permission set only to people who work with Banking.
- 365 Banking - Setup includes Banking (Base) and Banking - Release Bank Accounts, allows changing all setups and shows the Technical details FastTab on the bank access pages.
- Banking - Release Bank Accounts allows releasing customer and vendor bank accounts for payments.
- Banking SEPA Import (no recipient details) and (with recipient details) define separately, for SEPA payment imports, who may approve and carry out a payroll file and who may see each recipient line. See Who may see the recipients.
- Approvals: payments in the payment journal and SEPA payment imports can be bound to an approval workflow with a four-eyes principle. See Approvals.
- Second signature at the bank: with EBICS via VEU. See Second signature at the bank.
For details, see Permissions and licenses.
Endpoints and firewall
Connections are established from the Business Central server. With Business Central online, no setup is required. For on-premises installations, these addresses must be reachable over HTTPS (port 443):
| Address | Purpose |
|---|---|
api.365businessapi.com | PSD2/XS2A via finAPI, verification of payee, EBICS |
license.365businessapi.com | license check |
banking.365businessapi.com | Shopify sign-in, payment service provider redirect pages |
api.stripe.com | Stripe |
api-m.paypal.com | PayPal |
*-checkout-live.adyenpayments.com, ca-live.adyen.com, balanceplatform-api-live.adyen.com | Adyen (collection, settlement reports, transactions via the Balance Platform) |
api.unzer.com | Unzer |
api.klarna.com | Klarna |
api.mollie.com | Mollie |
<your shop>.myshopify.com | Shopify |
pay-api.amazon.eu, pay-api.amazon.com, pay-api.amazon.jp | Amazon Pay, per region |
*.amazonaws.com (Amazon S3) | downloading the Amazon Pay settlement report via a pre-signed URL |
Your bank's web form and the providers' sign-in pages open in the user's browser. For this, pop-ups must be allowed for Business Central.
During installation, 365 business Banking turns on Allow HttpClient Requests in its Extension Settings. If you revoke this permission, retrieval, payment and verification of payee are no longer possible.
Retention
For three tables containing account data, you can define a retention period under Retention Policies: Bank Transaction Detail, EBICS Job and Payment Import Header (SEPA payment imports). 365 business Banking does not create a policy. Without a policy, the data is kept indefinitely. For recommendations, see Retention policies.
Telemetry
365 business Banking sends technical telemetry to the publisher's Application Insights and, if set up, to your environment's Application Insights. The telemetry contains which function ran, for how long and with what result, and for errors also the message and call stack. Responses from banks and payment service providers are not transferred in full, only filtered down to technical fields such as status and error codes. Credentials, tokens and transaction data are not included.
