Your Documents. Protected at Every Layer.

You're uploading master contracts and invoices, the most sensitive financial documents in your company. PayAudit is built with encryption, strict data isolation, and a clear AI data policy so you can audit with confidence.

🔒 Encryption

Data is encrypted in transit and sensitive credentials are encrypted at rest. We use proven cryptographic standards throughout the application.

🏠 Data Isolation

Each organization's data is logically isolated at the application level. All API queries are scoped to prevent cross-tenant data access.

👤 Access Controls

Role-based access control ensures users only see what they need to. Actions are logged for accountability.

🤖 AI Data Policy

We take a strict, transparent stance on how your data interacts with AI. Your financial documents are processed to generate your audit, nothing else. They are never used to train, fine-tune, or improve any AI model.

📊 Data Retention & Deletion

You control your data lifecycle. We provide delete functionality so data is removed when you request it.

PayAudit's database is hosted on Neon, a managed PostgreSQL provider. Neon automatically creates point-in-time backup snapshots as part of its infrastructure. Free-plan databases retain these automated backups for up to 7 days; paid plans retain them for up to 30 days. These backups exist solely for database recovery purposes — PayAudit employees cannot access individual user records through them, and they are managed entirely by Neon's infrastructure team. If your account is deleted or you request full data erasure, production records are removed immediately; backup copies will naturally expire within the applicable retention window (7 or 30 days). Users who require written confirmation of full backup purge beyond the standard window may contact privacy@payaudit.com.

Compliance Readiness

PayAudit is designed with security best practices as a foundation. Our architecture choices are informed by leading security frameworks.

SOC 2-Ready

Security-First Architecture

Built with SOC 2 Trust Services principles in mind: encryption, access control, and data isolation. Formal certification is on our roadmap.

GDPR-Aligned

Data Subject Rights

Support for data access, rectification, and erasure. We can provide data export upon request.

Audit Logging

Activity Tracking

Audit execution logs track AI operations, costs, and results for operational transparency.

📄 GDPR & Data Processing Agreement (DPA)

PayAudit is committed to GDPR compliance. If your organization is based in the EU or UK, you may require a Data Processing Agreement (DPA) before using PayAudit.

Lawful Basis Documented
All processing activities have a defined legal basis under GDPR Art. 6
🔒
Data Subject Rights
Self-service data export, deletion, and consent management in-app
📋
DPA Available
Data Processing Agreement template available on request
📅
Configurable Retention
Admin-configurable retention policies with auto-expiry and 30-day warning emails

To request a DPA: Email privacy@payaudit.com with subject line "DPA Request" and your organization name. We'll respond within 3 business days.

Our standard DPA covers: controller/processor roles, processing activities, security measures, sub-processor list, data transfers, and GDPR Article 28 requirements.

Request DPA →

📧 Vulnerability Reporting

If you discover a security vulnerability, please report it to security@payaudit.com. We take all security reports seriously and will work with you to resolve issues promptly.

We operate a responsible disclosure policy and welcome input from the security research community.