You're uploading master contracts and invoices, the most sensitive financial documents in your company. PayAudit is built with encryption, strict data isolation, and a clear AI data policy so you can audit with confidence.
Data is encrypted in transit and sensitive credentials are encrypted at rest. We use proven cryptographic standards throughout the application.
Each organization's data is logically isolated at the application level. All API queries are scoped to prevent cross-tenant data access.
Role-based access control ensures users only see what they need to. Actions are logged for accountability.
We take a strict, transparent stance on how your data interacts with AI. Your financial documents are processed to generate your audit, nothing else. They are never used to train, fine-tune, or improve any AI model.
You control your data lifecycle. We provide delete functionality so data is removed when you request it.
PayAudit's database is hosted on Neon, a managed PostgreSQL provider. Neon automatically creates point-in-time backup snapshots as part of its infrastructure. Free-plan databases retain these automated backups for up to 7 days; paid plans retain them for up to 30 days. These backups exist solely for database recovery purposes — PayAudit employees cannot access individual user records through them, and they are managed entirely by Neon's infrastructure team. If your account is deleted or you request full data erasure, production records are removed immediately; backup copies will naturally expire within the applicable retention window (7 or 30 days). Users who require written confirmation of full backup purge beyond the standard window may contact privacy@payaudit.com.
PayAudit is designed with security best practices as a foundation. Our architecture choices are informed by leading security frameworks.
Built with SOC 2 Trust Services principles in mind: encryption, access control, and data isolation. Formal certification is on our roadmap.
Support for data access, rectification, and erasure. We can provide data export upon request.
Audit execution logs track AI operations, costs, and results for operational transparency.
PayAudit is committed to GDPR compliance. If your organization is based in the EU or UK, you may require a Data Processing Agreement (DPA) before using PayAudit.
To request a DPA: Email privacy@payaudit.com with subject line "DPA Request" and your organization name. We'll respond within 3 business days.
Our standard DPA covers: controller/processor roles, processing activities, security measures, sub-processor list, data transfers, and GDPR Article 28 requirements.
If you discover a security vulnerability, please report it to security@payaudit.com. We take all security reports seriously and will work with you to resolve issues promptly.
We operate a responsible disclosure policy and welcome input from the security research community.