Security at Payle.
How Payle protects your account, your data and your AI spending, and how to report a security issue to our team.
Security by design
Payle is built as a financial product from day one: least-privilege access, encrypted storage and review gates on every release. Production systems are reachable only by the engineers who need them, always with multi-factor authentication and audit logging.
Encryption in transit and at rest
Traffic between your browser and Payle is encrypted with TLS 1.3. Data at rest, including account, usage and repayment records, is encrypted with AES-256. Card credentials are tokenized by our payment partners, and Payle never stores your full card number.
Payments and compliance
Card issuing and money movement run on regulated banking partners and PCI-DSS Level 1 infrastructure. We never sell personal data, and we keep only the information we need to underwrite, protect and support your account.
AI and your data
Credit decisions combine your application and product usage signals under human oversight, with the reasoning available to our risk team. Your financial data stays with Payle: it is never used to train third-party AI models, and you can request an explanation or a human review of any automated decision.
You stay in control
Every account supports multi-factor authentication, session management and instant card controls. Set per-transaction and monthly spend limits, whitelist approved merchants, freeze or revoke a virtual card in one click, and export your activity whenever you want.
Reporting a vulnerability
If you believe you found a security issue, report it privately to security@usepayle.com. Our responsible disclosure guidelines and Bug Bounty terms are published in the security research page.