PayUp Hub
Log inStart free
Security architecture

Controls are evaluated on the server, not implied by the interface.

A verified identity is only the start. Company membership, status, role permissions, resource scopes, feature entitlements, limits, and workflow state are checked again for every sensitive action.

Identity

Supabase email/password identitySingle-use email verification and recovery linksHttpOnly, Secure, SameSite session cookiesNo ChatGPT identity dependency

Tenant isolation

Active company accepted only after membership validationCompany ID carried through every business queryTenant-specific object keys for documentsNo authorization from client-provided metadata

Authorization

Role-to-permission mappingResource scopesFeature and plan entitlementsPayroll separation of duties

Evidence and recovery

Actor, company, target, reason, and correlation audit contextHashed source network identifierIdempotency for payroll preparationDocumented backup, restore, and incident procedures
Current release: production-oriented sandbox

PayUp Hub does not debit accounts, send deposits, calculate authoritative taxes, file returns, remit funds, or replace professional payroll and legal review. Those actions require configured regulated providers and launch approval.