Skip to main content
Governance

Security Practices

Effective Date: August 4, 2026

This statement describes the safeguards that protect RunPayway™ and the records organizations keep in it. It describes what is implemented today, not what is planned.

1.Purpose

This statement outlines the safeguards implemented to protect the integrity of the RunPayway™ service and the records it holds for organizations.

It is a high-level overview and does not disclose detailed technical configuration.

It is informational and is not a guarantee of security. RunPayway™ has not completed an independent security audit and holds no security certification.

2.Service Architecture Controls

RunPayway™ includes technical and administrative safeguards, including:

  • a deterministic engine that is separated from the interface that calls it
  • records that are owned by exactly one organization
  • authentication required before any organizational record can be reached
  • server-side authorization on every read and write of an organizational record

These controls are part of the service design rather than a setting an operator can turn off.

3.Data Protection Measures

Implemented measures include:

  • transport encryption using HTTPS, with HSTS set on responses
  • passwords stored only as salted hashes derived with a slow key-derivation function, never in readable form
  • session tokens generated from a cryptographically secure source, stored only as hashes, and given a fixed expiry
  • session cookies restricted to the site, marked HttpOnly, and marked Secure outside local development
  • sign-in failures returned as a single generic message that does not reveal whether an account exists

Every read and write of a record is scoped on the server to the organization of the signed-in user.

RunPayway™ does not handle payment card numbers, bank credentials, or credit bureau data.

4.Access Controls

Access to an organization's records is limited to users that organization has authorized. The service uses:

Named staff roles. An organization administrator manages the organization's users and settings. An assessor creates and updates records. A read-only reviewer can view records but cannot change them.

Role and organization membership are read from the server-validated session on every request. They are never taken from a form field, a URL parameter, or any other value supplied by the browser.

5.Logging and Monitoring

Structured logging supports:

  • service integrity
  • abuse detection
  • operational review
  • investigation of reported problems

Logs are retained only as long as needed for operational integrity, and are not used to profile individuals.

6.Third-Party Service Providers

RunPayway™ relies on third-party providers for infrastructure hosting and network delivery.

Those providers maintain their own security practices.

RunPayway™ does not warrant or represent the security practices of third-party providers.

RunPayway™ has no integration with any bank, credit bureau, payroll provider, or lender system, and sends no record data to one.

7.Incident Evaluation and Response

Security incidents are evaluated based on the potential risk to the service or to personal information.

If a confirmed incident affects personal information, PeopleStar Enterprises, Inc. will take appropriate steps consistent with applicable law and will notify affected organizations.

Response actions may include:

  • investigation
  • containment
  • remediation
  • notification, where legally required

8.Responsible Disclosure

If you identify a potential security vulnerability, you may submit a report through the RunPayway™ contact form.

Reports are reviewed in line with internal security procedures. Please do not test against another organization's data.

9.Limitations

No system can be guaranteed to be completely secure.

RunPayway™ does not warrant that unauthorized access will never occur.

Organizations are responsible for authorizing only the staff who need access, for assigning the least role that fits the work, and for removing access when a staff member leaves that role.

10.Continuous Review

Security practices are reviewed periodically and may be updated as the service develops.

Updates will not alter previously issued results.

11.Framework Alignment

RunPayway™ is built with recognized security and privacy frameworks in mind. No certification has been obtained and no independent audit has been completed. The frameworks the work is measured against are:

  • SOC 2 Trust Services Criteria, used as a reference for control design. RunPayway™ is not SOC 2 certified.
  • ISO 27001, used as a reference for risk assessment, access control, and continuous improvement. RunPayway™ is not ISO 27001 certified.
  • GDPR, whose data minimization, purpose limitation, and data subject rights principles inform how the service handles information.
  • CCPA and CPRA, whose access, deletion, correction, and opt-out rights inform the privacy request process.

Framework alignment is not certification. This section will be updated if formal audit milestones are reached.

Organizations that need further security documentation may request it through the contact form.

Contact Us for Security Questions

If you have a concern or need more information about these practices, reach out through the RunPayway™ contact form.

Contact Us

RunPayway™ financial proof infrastructure.

The Financial Proof Network. RunPayway™ establishes a requested financial fact from authorized evidence and issues a proof that can be independently verified.

Prove what matters. Share less.

RunPayway™ provides financial proof infrastructure. It is not financial, legal, tax, or investment advice, and it is not an underwriting or lending decision. A RunPayway™ proof states what was established from authorized evidence. It is not an approval, a guarantee, or a recommendation to proceed, and a result of NOT VERIFIED is not a denial or a judgment about any person. The recipient retains full responsibility for its own decision.