MarkPaid
How it worksFeaturesPrivacySecurity
Log inRequest access
How it worksFeaturesPrivacySecurity
Security at MarkPaid

Safeguards for every receivables workflow.

MarkPaid is designed to protect customer data, keep each account isolated, and preserve a traceable record of sensitive activity. This page summarizes the controls we use today and the assurance work still in progress.

Security program

Current as of
July 18, 2026
Maintenance owner
Security and Compliance, Bspoke Ventures Inc.
Assurance status
SOC 2 Type 1 readiness in progress

Security controls

How we protect customer data and systems

Our controls layer technical safeguards with documented operating practices. We publish enough detail to support customer diligence without exposing sensitive configurations or procedures.

Encryption and secrets

Customer-facing traffic and authenticated integrations use encrypted connections. Production data uses provider-supported encryption at rest, while credentials and secrets are restricted to authorized server-side paths and excluded from application logs.

Tenant isolation and access

Customer data is scoped by account. Authentication, role- and account-based authorization, and database Row Level Security work together to limit access. Privileged support access is server-only, time-boxed, and recorded in an audit log.

Managed infrastructure

MarkPaid runs on managed cloud hosting, authentication, database, and workflow platforms. We remain responsible for secure configuration, access, tenant isolation, monitoring, incident response, and ongoing vendor review.

Secure development

Changes are reviewed through pull requests, tested in separated development or preview environments, and approved before production deployment. Automated dependency, security, and business-invariant checks support each release, with deployment history available for rollback.

Monitoring and response

Availability, application errors, workflows, database connectivity, and relevant integrations are monitored. A documented incident-response process covers reporting, triage, investigation, containment, recovery, documentation, and required notifications.

Independent assurance

MarkPaid has completed an external penetration test. Detailed findings and other sensitive security evidence are shared through controlled review channels when appropriate, rather than published in a way that could weaken the service.

Product security

Secure development and change management

Security is part of how changes move from development into production, with reviewable evidence retained in source control and deployment history.

  • Peer review and approval for production source changes
  • Automated dependency, vulnerability, and security-regression checks
  • Tests for tenant isolation and payment-aware workflow safeguards
  • Documented deployment monitoring and rollback procedures

Governance

Controls are maintained, reviewed, and evidenced

Security and compliance practices have named ownership and recurring review cycles so published commitments can stay aligned with the system we operate.

  • Access, security, and operating policies reviewed at least annually and after material changes
  • Periodic access, vendor-risk, vulnerability, backup-recovery, and control reviews
  • Append-only product and privileged-access audit records for sensitive activity
  • Data retention and secure disposal practices based on legal, contractual, operational, and security needs
Readiness in progress

Our SOC 2 status, stated plainly.

Bspoke Ventures Inc. is preparing MarkPaid for a SOC 2 Type 1 point-in-time examination. The formal examination has not begun, and no SOC 2 report has been issued.

MarkPaid does not currently claim a SOC 2 attestation, and a Type 2 examination period has not been completed. Readiness work includes formalizing controls, collecting evidence, testing safeguards, and maintaining security and privacy documentation.

Our privacy program is designed to support applicable Canadian privacy obligations, including PIPEDA and Quebec’s private-sector privacy law. See our Privacy Policy for details.

Security questions or a suspected issue?

Contact our security team for procurement reviews, controlled evidence requests, or vulnerability reports. Please do not include credentials or sensitive customer or financial data in your first email.

Security researchers can also review our security.txt.

Contact security

Product

  • How it works
  • Features

Company

  • Security
  • Contact

Legal

  • Privacy
  • Terms
© 2026 MarkPaid. Invoice follow-ups that stop when you get paid.