PAYOUP

Security Agreement

Payoup is committed to maintaining the highest standards of data security and protecting your information.

Last updated: September 2026

1. Introduction

At Payoup, we take security seriously. This Security Agreement outlines our commitment to protecting your data, financial information, and privacy through industry-leading security measures and best practices.

2. Scope of Application

This Security Agreement applies to all users of Payoup services, including service providers, customers, and any third parties who access or interact with our platform. It covers:

  • All payment transactions processed through Payoup
  • Storage and processing of personal and financial data
  • Access to Payoup platform and API services
  • All communications and data exchanges with Payoup

3. Data Security

Payoup employs multiple layers of security to protect your data:

  • End-to-end encryption for all data transmissions
  • Regular security audits and penetration testing
  • Advanced firewall and intrusion detection systems
  • 24/7 security monitoring and incident response
  • Secure data centers with physical security measures

4. Encryption

All sensitive data is encrypted using industry-leading encryption standards:

  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit
  • End-to-end encryption for payment data
  • Regular encryption key rotation and management

5. Access Control

Payoup implements strict access control measures:

  • Role-based access control (RBAC) for all systems
  • Multi-factor authentication (MFA) for all user accounts
  • Principle of least privilege for data access
  • Regular access reviews and privilege escalation controls

6. Monitoring

Continuous monitoring and threat detection:

  • Real-time threat detection and alerting systems
  • Anomaly detection using machine learning
  • Security information and event management (SIEM)
  • Regular security metrics and compliance reporting

7. Incident Response

In case of a security incident:

  • Immediate incident response team activation
  • Incident containment and mitigation procedures
  • Notification to affected users within required timeframes
  • Post-incident review and security improvements

8. Compliance

Payoup maintains compliance with major security standards:

  • PCI DSS compliant payment infrastructure
  • GDPR data protection requirements
  • UK Data Protection Act 2018
  • Industry-standard information security practices

9. User Responsibilities

You play a crucial role in maintaining security. Please:

  • Keep your login credentials secure and confidential
  • Enable multi-factor authentication
  • Regularly review your account activity
  • Report suspicious activity immediately

10. Password Security

Password security requirements and best practices:

  • Use strong, unique passwords for your Payoup account
  • Change passwords regularly
  • Never share your password with anyone
  • Use a password manager for secure storage

11. Fraud Prevention

Fraud prevention measures employed by Payoup:

  • AI-powered fraud detection systems
  • Real-time transaction monitoring
  • Behavioral analysis and anomaly detection
  • Cross-referencing with known fraud databases

12. Data Breach

In the event of a data breach, Payoup will: Notify affected users promptly, investigate the breach thoroughly, cooperate with regulatory authorities, implement corrective measures to prevent future incidents, and provide credit monitoring services where applicable.

13. Contact

For security-related inquiries or to report a vulnerability, please contact our security team at Payoup.

13. Contact

security@payoup.com
Enexfi LTD, 128 City Road, London, EC1V 2NX, UNITED KINGDOM