Security
Our security approach
PaidSoon is operated by Syspac Pty Ltd. We take the security of your invoice data and account credentials seriously. The following describes our key security practices.
Data protection
- All data is encrypted in transit using TLS.
- Database access is protected by row-level security (RLS) policies.
- OAuth tokens for connected accounting providers are encrypted at rest.
- Authentication is provided by Supabase Auth with support for multi-factor authentication.
Infrastructure
PaidSoon is built using modern managed cloud services, including:
- Vercel for hosting the web application
- Supabase for database, authentication and storage services
- Stripe Connect for secure payment account authorisation
- email delivery infrastructure for transactional invoice reminders and account notifications
We use managed providers so that security updates, availability controls and platform monitoring can be handled using established cloud infrastructure. Data residency and provider-region details may vary depending on the services used and will be reviewed as PaidSoon moves from private beta to production.
Access control
Access to PaidSoon systems is limited to authorised personnel. Administrative access is protected using strong authentication and least-privilege principles wherever practical.
Audit logging
PaidSoon records key events such as account connection, invoice sync, reminder sends, promise-to-pay updates, dispute pauses and manual workflow actions.
Responsible disclosure
If you believe you have found a vulnerability, contact security@paidsoon.com.au. Please include enough detail for us to reproduce the issue and do not publicly disclose the issue until we have had a reasonable opportunity to investigate.