Security at PaidVora

How we protect your workspace, your QuickBooks data and your customers.

Workspace isolation

Every workspace is tenant-isolated. The data of one workspace is accessible only to that workspace's members, and every database query is scoped to the workspace of the signed-in user.

Accounting-firm portfolios keep each client company in its own isolated workspace. Firm users see only the client workspaces they are explicitly assigned to, and clients never see each other.

QuickBooks access is read-only

PaidVora connects to QuickBooks Online with read-only access. We read overdue invoices and customer records; we never create, modify or delete anything in your QuickBooks company.

Sample and sandbox QuickBooks connections are permanently blocked from customer delivery.

Authentication and multi-factor verification

Passwords are hashed and managed by our authentication provider; we never store or display them.

Multi-factor authentication (TOTP authenticator apps) is available to every account and required for owners, admins and all platform administration. Sensitive actions re-verify that the current session is MFA-verified before they run.

Password reset links are single-use and expire, and accounts with MFA must also enter an authenticator code to complete a reset.

Delivery safeguards

No email is sent without a person approving it first. Delivery starts disabled in every workspace and must be turned on explicitly.

Scheduled sending re-checks QuickBooks before each email goes out, so paid, voided or deleted invoices are never chased. Customer replies pause follow-up automatically.

Delivery eligibility is fail-closed: if any required setting or check cannot be confirmed, nothing is sent.

Audit history

Approvals, policy changes, delivery decisions, role changes and administrative actions are recorded in a per-workspace audit history.

Platform administration is audited as well, and administrators can never impersonate a workspace user.

Payments and secrets

Payments are processed by Stripe. PaidVora never sees or stores your full card number.

Connection credentials and signing secrets are stored encrypted, never appear in the browser, and are never written to logs or emails.

Webhooks from Stripe, QuickBooks and our email provider are verified for authenticity before they are processed.

Your data and requests

Workspace owners can request a copy or deletion of their data from the Support area under “Privacy / Data request”. Requests are identity- and ownership-verified and processed manually; nothing is deleted automatically.

We retain information only as reasonably necessary for account administration, security, fraud prevention, dispute resolution and legal or accounting obligations.

Report a security concern

If you believe you have found a security issue, email support@paidvora.com with the details. Please do not include passwords, card numbers or QuickBooks credentials in your message.