Security
Trustworthy by design. Honest about our limits.
Card payments run on Stripe's infrastructure, not ours. Stored secrets are encrypted at rest, every business's data is kept strictly separate, and the bank-transfer details your client sees are frozen the moment you send — so nothing changes on them after the fact.
Our approach
Security is a set of practices, not a badge.
We'd rather tell you plainly what's in place today than reach for language that implies more than we've actually built. SimplePayment doesn't try to reinvent payment security — it leans on Stripe for the parts Stripe does best, keeps every business's data separate, and applies the standard hardening every modern web application should have. Where we haven't built something yet — a formal compliance certification, for instance — the FAQ below says so directly.
In practice
What that means day to day.
Card payments run on Stripe
Checkout is hosted by Stripe. Card numbers are entered on Stripe’s page and never touch our servers.
Encrypted at rest
Stored secrets — your Stripe key, email credentials, webhook secret — are encrypted (AES-256-GCM) and never shown again once saved, only masked.
Your data, kept separate
Every business’s records are scoped to that business alone. Nothing is shared or visible across accounts.
Authenticated access
Sign in with a hashed password or Google, and a password reset never reveals whether an email has an account.
No duplicate charges from a hiccup
Payment notifications are checked for duplicates, so a network retry can’t charge — or record — the same payment twice.
Hardened by default
Standard protections — rate limiting, secure headers, restricted cross-origin access — run on every request, not bolted on later.
Privacy
Your data is used to run your invoicing — not sold, not shared.
The full detail on what's collected, why, and for how long lives in our Privacy Policy, including how third-party providers like Stripe fit in.
Responsible disclosure
Found something? Tell us directly.
We don't run a formal bug-bounty program today. If you believe you've found a security issue, email support@simplepayment.io with what you found — we read every report and will follow up.
Questions
Straight answers on security.
Do you ever see or store my client’s card number?
No. Card entry happens on Stripe’s hosted Checkout page. SimplePayment never receives or stores raw card numbers.
Do you have SOC 2, ISO 27001, or PCI certification?
Not today, and we won’t claim otherwise. Card payments are processed through Stripe’s PCI-compliant infrastructure, so SimplePayment never stores, processes, or transmits raw card data. As a result, SimplePayment itself does not currently hold separate SOC 2, ISO 27001, or PCI certifications.
Where is my data hosted?
In the EU, on MongoDB Atlas infrastructure in Stockholm, Sweden.
Can other businesses on SimplePayment see my data?
No. Every record — clients, invoices, payment settings — is scoped to your business alone.
I think I’ve found a security issue. What do I do?
Email us directly at support@simplepayment.io with as much detail as you can. We don’t yet run a formal bug-bounty program, but we take every report seriously and will respond.
Received an invoice and want to check it's real? Why we built it this way More questions? Visit the Help Center
For businesses that need their clients' trust, not just their payment.
Get paid on infrastructure built to be trusted.
Free to start · No credit card