Skip to content
Security

What we actually do with your payroll data.

Paylio holds salaries, national IDs and bank accounts for every person in your company. It is built and operated by Serviq BPO Limited of Dhaka, Bangladesh. This page describes the controls that are in the product today — and, at the bottom, the ones we are not going to pretend we have.

How the product is built

  • Personal identifiers are encrypted in the database

    National ID, TIN, passport number, bank account and routing number, MFS wallet number and provident-fund account are not stored as readable text. Each is encrypted with AES-256-GCM before it reaches Postgres and stored as raw bytes, so a copy of the database — or of a backup of it — is opaque without the key.

  • The keys live outside the database

    Encryption keys are supplied to the application as environment configuration, never stored in the data they protect, and are versioned so a key can be rotated without making older records unreadable. In production the service refuses to start at all if the keys are missing, rather than quietly writing the next record in plain text.

  • Every action is re-checked on the server

    A button you cannot see is not a permission you do not have. Each endpoint declares the permission it requires and the server enforces it on every request, so removing a control from the interface is never what stops an action — the backend is.

  • One organisation cannot read another

    Paylio is multi-tenant, and every query that touches organisation-scoped data is filtered by the organisation of the signed-in user. It is treated as a security defect, not a bug, if a query is written without that filter.

  • Roles, including the ones you define

    Access is role-based: admin, HR, finance, manager, auditor and employee, plus custom roles an organisation builds from the same permission set. A custom role is enforced by exactly the same server-side check as a built-in one.

  • Sensitive reads are logged

    Looking at an employee's salary or identifiers is recorded in a dedicated sensitive-access log, separate from the platform audit log that records administrative actions. Access to payroll data is therefore reviewable after the fact, not only preventable before it.

  • Records are retired, not erased

    Organisations, user accounts and payroll records are soft-deleted — their status changes and the deletion is timestamped, but the row remains. Payroll history stays reconstructable for the statutory period instead of disappearing on a misclick.

  • Logs are written without personal data

    Application logs are structured JSON with a request trace, and personal fields are stripped by name before a line is written — email, phone, national ID, TIN, bank account, salary. Request bodies and query strings are never logged at all.

  • Backups are encrypted and kept off the server

    Database dumps are encrypted to a public key before they leave the machine, and only the matching private key — held separately from the backups — can open them. Restores are exercised against the same encrypted artefacts.

  • Traffic is encrypted in transit

    Paylio is served over HTTPS only, and session cookies are marked Secure so a session token is never transmitted in the clear.

What we don’t claim

Security pages tend to imply more than they say. Ours says it:

  • We hold no third-party security certification, no external audit of our controls has taken place, and no independent assessment of the running system has been commissioned. If your procurement process needs an auditor's report, we do not have one to hand you — so you will not find a badge for one anywhere on this site.
  • We do not run a paid vulnerability-reward programme. We will still read and act on anything you report to us.
  • We do not claim compliance with any particular data-protection statute. What we owe your organisation is what the Terms of Service and the Privacy Policy say we owe it.
  • We do not claim that every copy of your data stays inside Bangladesh. Where a sub-processor holds data elsewhere, the Privacy Policy is what describes it.

Reporting a problem

If you believe you have found a vulnerability in Paylio, write to privacy@mypaylio.com with enough detail to reproduce it. Please do not probe another organisation’s data. There is no reward on offer, but we will acknowledge your report and tell you what we did about it.

How we handle personal data, and who processes it on our behalf, is in the Privacy Policy. Cookies are described in the Cookie Policy.