Pay4U legal
Security Practices
Pay4U treats every balance, mandate and instruction as a sensitive record. These are the controls that protect them.
Last updated: 2 September 2026
Data isolation
Wallets, transactions, mandates and audit logs are protected by row-level security. Every query runs as the signed-in user, so one account can never read or write another account's records, even if application code is bypassed.
Encryption
- TLS 1.2+ for all traffic between your device and Pay4U.
- Encryption at rest for the database, object storage and backups.
- Secrets and provider API keys are held in a managed secret store, never in application code.
Authentication
- Email and password sign-in with hashed credentials and session tokens that rotate.
- Self-service password reset through a time-limited, single-use link.
- Session revocation on sign-out across the device that initiated it.
Audit logging
Wallet allocations, mandate approvals, bill payments and card controls are written to an append-only audit log with the acting user and a server-side timestamp before the interface confirms the action. Audit entries cannot be edited or deleted by users.
Monitoring and change control
- Least-privilege access to production, granted per role and reviewed regularly.
- Automated dependency and database security scanning on every change.
- Reconciliation jobs that compare our ledger against provider statements and flag mismatches.
Responsible disclosure
If you believe you have found a vulnerability, contact us before disclosing it publicly. We will acknowledge within 48 hours, keep you updated and will not pursue action against good-faith research that avoids privacy violations, service disruption and data destruction.