Security
Last updated: May 16, 2026
PaidLens is designed for sensitive commission, payout, and compensation data. Security is built into the platform through organizational isolation, access controls, authentication protections, and auditability.
1. Access Control
- Role-based access control for users, managers, admins, and super admins.
- Organization-level tenant isolation so each customer only accesses its own data.
- Multi-factor authentication support.
- SSO/OIDC capabilities for enterprise customers where configured.
- Administrative visibility into user roles and account status.
2. Data Protection
- Encryption in transit using TLS.
- Encryption at rest where supported by infrastructure and database/storage providers.
- Logical separation of customer data by organization.
- Secure handling of authentication cookies and session tokens.
- Backup and recovery practices designed to support business continuity.
3. Monitoring and Auditability
- Activity logs for administrative and sensitive platform actions.
- Security-relevant application logs for troubleshooting and investigation.
- Monitoring for unusual access patterns, errors, and platform health issues.
4. Responsible Disclosure
If you believe you have found a security vulnerability, please contact us at [email protected]. Please include enough detail for us to reproduce and assess the issue. Do not access, modify, or exfiltrate customer data.
5. Contact
For security questions, contact [email protected].