---
title: "Security at RealPayee: how verification works and what data we keep"
description: "An honest security overview for finance and IT buyers: how RealPayee verification works, why it never moves money or handles payment credentials, what data the website stores and how, and how to request security documentation."
url: https://realpayee.com/trust/security
canonical: https://realpayee.com/trust/security
date_published: 2026-10-05
date_modified: 2026-10-05
author: RealPayee
---

# Security at RealPayee

> RealPayee never moves money and never asks for bank logins or payment credentials. It reads vendor bank-detail changes and payment requests from your ERP or AP tool, holds them, confirms them with the real person out-of-band, then releases or blocks them and records the result. We keep the minimum data needed for that record. We do not currently hold SOC 2 or ISO 27001 certification.

_Published 2026-10-05 · Updated 2026-10-05 · By RealPayee_

## How verification works

1. **Detect.** RealPayee connects to NetSuite, QuickBooks, Xero, Bill.com or Ramp and watches for vendor bank-detail changes and payments above the threshold you set.
2. **Hold.** The change or payment is held so it cannot be paid against until it is confirmed.
3. **Confirm out-of-band.** RealPayee contacts the vendor's known contact from your records, or the real executive, by SMS, Slack or Microsoft Teams. Confirmation is a phone-bound approval or a government ID plus live selfie check. Contact details in the request itself are never used.
4. **Release or block.** Once confirmed, the item is released in your system. If confirmation fails or is declined, it stays blocked for your team to review.
5. **Record.** Who confirmed, on which channel, when, and the outcome are kept as an audit record for your auditors and cyber insurer.

## What RealPayee never does

- **Never moves money.** Payments are made by your existing ERP, AP platform and bank. RealPayee only holds and releases.
- **Never handles payment credentials.** We do not ask for online banking logins, card numbers or any other payment credentials.
- **Never uses contact details from the request** being verified.
- **Never sells data** or uses it for advertising.

## Data minimization

We aim to keep only what a verification record needs: the item being verified, the contact verified against, the channel, timestamps and the outcome. Identity checks (ID plus live selfie) are used to confirm a person at a moment in time; we can describe exactly what is retained, and for how long, in our security documentation.

## What this website stores

- **Demo requests and sign-in attempts** are stored in a Supabase (Postgres) database. Row Level Security is enabled with no access policies, and the public database roles have no privileges on these tables, so these tables cannot be read or written from outside our own server.
- **Writes go through two database functions** that rate-limit submissions per visitor.
- **IP addresses are never stored in plain form.** We keep a salted SHA-256 hash, used only for rate limiting and abuse prevention.
- **No payment information, bank details or government ID** is collected on this website.
- **The site is hosted on Cloudflare.** See our [privacy policy](https://realpayee.com/privacy) for retention and your rights.

## Certifications

RealPayee does not currently hold SOC 2, ISO 27001 or similar certifications. We would rather say so plainly than imply otherwise. If your vendor review requires a questionnaire, architecture overview or data-flow description, we will complete it.

## Security questions and documentation

Email [hello@realpayee.com](mailto:hello@realpayee.com) for security documentation, a vendor questionnaire, or to report a vulnerability. For a walkthrough of the verification flow on your own systems, [book a demo](https://realpayee.com/demo).

## Frequently asked questions

### Does RealPayee have SOC 2?

No, not currently. We do not claim any certifications. We can complete your security questionnaire and provide documentation on request at hello@realpayee.com.

### Does RealPayee need access to our bank account?

No. RealPayee does not move money and does not need bank logins or payment credentials. It works with the vendor and payment records in your ERP or AP tool.

### What happens if a vendor never confirms?

The change or payment stays held, so nothing is paid against it until a person follows up using your fallback process, such as a callback to a known number.

### Where is website form data stored?

In a Supabase Postgres database with Row Level Security on and no public access policies. IP addresses are stored only as salted hashes for rate limiting.

## Related

- [Book a RealPayee demo](https://realpayee.com/demo) - Book a demo of RealPayee: see vendor bank-change and high-value wire verification on your NetSuite, QuickBooks or Xero payment flow. (markdown: https://realpayee.com/demo.md)
- [Vendor verification: how to verify vendor bank details before you pay](https://realpayee.com/vendor-verification) - A practical guide to vendor verification for finance teams: how to confirm vendor bank-detail changes, run callbacks, and prevent vendor impersonation fraud. (markdown: https://realpayee.com/vendor-verification.md)
- [What is out-of-band verification?](https://realpayee.com/answers/what-is-out-of-band-verification) - What out-of-band verification means for payments and vendor changes, examples, why it beats replying to an email, and its limits. (markdown: https://realpayee.com/answers/what-is-out-of-band-verification.md)
- [Privacy policy](https://realpayee.com/privacy) - How RealPayee handles personal data. (markdown: https://realpayee.com/privacy.md)

---

Canonical HTML: https://realpayee.com/trust/security · Site index: https://realpayee.com/llms.txt · Book a demo: https://realpayee.com/demo
