Legal & safety
Security
Last updated:
Paym is being built to make sending and receiving money simple without making security invisible. Security controls are designed into identity, account access, recipient confirmation, payment routing and operational systems from the beginning.
Paym is currently under development and has not yet completed its general commercial launch. Some products, features, payment methods and jurisdictions described by Paym are planned, in development or available only for controlled testing. Where a regulated financial service is made available, Paym will identify the entity providing that service, its regulatory status and the applicable terms before the customer uses it.
Protecting your Paym account
We use technical and organisational controls intended to reduce unauthorised access to Paym accounts. Depending on the feature and risk level, Paym may require additional verification before allowing sensitive account or payment actions.
Paym is designed to use controls such as:
- authenticated account access
- email and account verification
- session security
- step-up verification where appropriate
- access controls
- account and transaction monitoring
- limits or additional verification for sensitive actions
Additional verification is not required for every action, and not every account has every control enabled at all times.
Protecting information
Paym is designed to protect information in transit and at rest using appropriate security controls. Access to sensitive production systems and personal information is restricted according to operational need and system permissions.
Payment safety
Before a payment is authorised, Paym is designed to make the recipient, amount, currency, applicable fee, exchange rate where relevant, recipient amount and expected delivery information clear whenever those details are available for the selected payment route.
Depending on the feature and route, Paym may also apply:
- recipient verification
- fraud and risk checks
- provider and jurisdiction checks
- transaction records
- controlled routing
These controls are intended to reduce risk. They cannot guarantee that fraud, error or misuse will always be prevented.
Infrastructure and access
Paym operational systems are designed around:
- least-privilege access
- environment separation where applicable
- controlled administrative permissions
- audit trails
- secrets management
- monitoring
- dependency and security maintenance
The specific controls in use evolve as the service expands.
Payment and verification partners
Some Paym functions may rely on banks, payment providers, identity-verification providers, card networks, infrastructure providers or other regulated partners. Those organisations operate their own security environments and may apply additional security requirements.
Security monitoring and incidents
We monitor Paym systems for security, availability and suspicious activity and maintain processes for investigating security events. If an incident creates a legal obligation to notify affected users or authorities, we intend to make the required notifications in accordance with applicable law.
Responsible disclosure
If you believe you have found a security vulnerability affecting Paym, please report it privately rather than testing it against other users or publicising it before we have had a reasonable opportunity to investigate.
Please write to legal@paym.com with the subject line Security report. Include enough information for us to understand and reproduce the issue.
Please do not include passwords, full payment credentials or unnecessary personal information in your report.
Current status
Paym continues to evolve before wider launch. Security controls, supported payment methods and operational procedures may change as the service expands. We will update this page when material security practices change.