Security at Paytrace
Last updated August 22, 2026
Where your data lives
Amazon Web Services, US East. The database and file storage are encrypted at rest; all traffic is TLS 1.2+ in transit. Database access is restricted to the application servers — there is no public endpoint.
HIPAA
EMR collections reports can contain patient names, which is protected health information. We operate under a Business Associate Agreement with AWS, keep PHI out of logs and email, and never use customer data to train models or for analytics.
Isolation and access
Every clinic is a separate workspace; queries are scoped to the workspace on every request. Roles (owner, admin, member) gate destructive actions. Passwords are hashed with bcrypt; sessions are encrypted, HTTP-only cookies.
Audit trail
Bank data is immutable once imported. Every match, unmatch, note, write-off, partial write-off and exclusion is a separate, reversible record with who and when.
Backups
Automated daily database backups (7 days) plus weekly snapshots retained for 90 days, encrypted, in a separate backup vault.
Payments
Card data never touches our servers — checkout runs inside Paddle, a PCI DSS Level 1 merchant of record.
Reporting a vulnerability
Email hello@paytracept.com with “security” in the subject. We acknowledge within 2 business days.