Beneficiaries & Destination Registry
A Beneficiary represents a validated, encrypted payment destination stored within your workspace. Agents and operators refer to beneficiaries by immutable UUIDs rather than passing raw telecom credentials in every payload.
🔒 Security & Privacy Guarantees
- Encrypted at Rest: All account numbers and phone numbers are encrypted with AES-256-GCM.
- Cryptographic Fingerprinting: A SHA-256 hash of the normalized destination is indexed to prevent accidental duplicate beneficiary registration and duplicate payouts.
- Masked in Audit Logs: Sensitive numbers appear masked in telemetry logs and API responses (e.g.
2547****1234orPayBill 150501 (Ref: ****456)). - Risk Aging: Lipafy tracks when a destination was created or last updated. If bank account numbers or phone numbers were modified within the last 48 hours, approval screens flag the destination with an elevated risk notice to guard against invoice manipulation.
