Stay secure with advanced protection from Brex
Need help? If you suspect unauthorized activity or notice illegitimate communications related to your Brex account, please call the number on the back of your card or sign in to your dashboard or Brex mobile app to chat with Brex Support.
How Brex protects you
Account security
Our priority is keeping your account safe with features that facilitate secure browsing, authorization, and authentication.
Data privacy
Protecting your privacy is core to how we’re building Brex. Read our Privacy Policy.
Fraud protection
Spend with confidence thanks to Brex’s advanced fraud monitoring and protection.
Fraud prevention
Brex can prevent fraud before it happens by ensuring that only authorized users can access accounts and make changes.
Account security
Secure browsing
Encryption
Our website uses industry-standard encryption to ensure protected transmission of data (HTTPS): AES-256 bit or better for RDS and S3 data encryption for data at rest and TLS 1.2 or better for transit.
Idle lockouts
Brex forces automatic signouts after inactivity to prevent unsanctioned access or use of the user’s account.
Security policy
Brex enforces a strict content security policy and iFrame protection to mitigate the threat of attacks such as ClickJacking.
Authentication
Secure ID and password
Brex enforces strong password requirements and supports mobile biometric authentication (Face ID/Touch ID).
Activity confirmation
Brex leverages both automated and manual review mechanisms to confirm account changes such as password resets.
Identity verification
Upon account creation, Brex customers are required to set up two-factor authentication so that even knowing a user's password is not enough to compromise their account.
Device verification
We require a one-time authorization for each browser on every device you use to sign in to Brex, which ensures that only your approved devices and IP addresses can access your Brex account.
Single Sign-On (SSO) integration
Brex Empower’s SSO feature enables a secure — yet seamless — login experience through Okta, OneLogin, Microsoft, Google Workplace, and more identity providers (IdPs).
Brex corporate security
Product security
Brex has a team of risk-minded information security professionals and experienced software engineers that are constantly building innovative and tailor-made features, services, and tools to protect customers.
Security by design
Security testing and code review –as well as mature logging, monitoring, alerting capabilities– are built into our engineering workflows, including the software development lifecycle.
Application security
Brex has a dedicated internal team of security engineers focused on the technical security of our web and mobile applications. We conduct ongoing penetration tests to proactively prevent weaknesses.
Incident response
Brex follows an established procedure for responding appropriately to potential incidents. All suspected incidents are managed by our Detection and Response team, which is supported by mature logging, monitoring, and alerting capabilities.
Built from scratch
Our experienced engineers built the critical components of our financial product in house to be in control. This allows us to easily make upgrades, patch systems, and continuously iterate on security.
Regulatory and standards compliance
Brex is SOC 2 Type II and PCI compliant, and Brex Cash is regulated by FINRA.