Certifications
- SOC 2 Type II, audited annually
- PCI DSS Level 1 for card-funded accounts
- Annual third-party penetration testing, summary available under NDA
Encryption
TLS 1.2 or higher in transit and AES-256 at rest. Bank account numbers and SSNs live in a separate store with their own keys, so a compromise of the primary database does not expose them.
Recommended configuration
- Require SSO and MFA for every role that can approve payroll
- Use a distinct API key per service, scoped to the companies it needs
- Enable bank-change notifications for admins
- Stream audit logs to your SIEM
Reporting a vulnerability
Send findings to security@payflo.dev. We acknowledge within one business day and do not pursue legal action against good-faith research that follows our disclosure policy.