Security Overview
Draft, last updated pending counsel review
Payroll data is sensitive by nature: it includes Social Insurance Numbers, compensation, and banking details. This page describes the safeguards RunPayroll applies, and is honest about what is not yet in place.
Encryption
All traffic is encrypted in transit. Stored records live in a managed Canadian-region database. Sensitive identifiers are designed for field-level encryption with keys held in a cloud key-management service, separate from the database.
Access control
- Role-based access on a two-axis permission model; users see only what their role in a given organization allows.
- Multi-factor authentication for administrative access.
- Firm access to client employers is scoped per assignment, not firm-wide by default.
Auditability
The Service keeps an append-only audit log of significant access and changes. Entries cannot be edited or deleted, by design.
Operations
Infrastructure runs on managed providers (listed at /subprocessors) with provider-managed backups. Generated documents are stored in object storage and served through expiring, signed links.
What is not yet in place
We do not yet hold a SOC 2 report and have not yet commissioned an independent penetration test. Both are planned as the product matures; we would rather say so than imply otherwise.
Reporting a vulnerability
Report suspected vulnerabilities to support@runpayroll.ca. We acknowledge reports and act on confirmed issues promptly.