Security — IncentivPay platform controls
    Trust · Security

    Security controls, in plain language.

    This page is maintained by IncentivPay to describe the security controls currently enabled on the platform. It is not an independent certification.

    Illustrative view of security controls

    Enabled controls

    Authentication
    Merchant, customer, and admin surfaces run on managed auth with Google OAuth and password + email flows.
    Role separation
    Access enforced via a dedicated roles table with SECURITY DEFINER checks — not client-side flags.
    Data isolation
    Row-level security enforced on every user-facing table. Merchant staff see only their location's data.
    Payments
    Card processing runs through Stripe. IncentivPay never stores raw card numbers or CVV.
    Audit logs
    Every AI recommendation, override, and payout is written to an append-only decision log.
    Encryption
    TLS in transit and database encryption at rest via the managed cloud backend.
    Shared responsibility

    What we operate. What you configure.

    IncentivPay operates the platform: authentication, encryption, database security, row-level policies, and the incentive engine.

    Merchants configure: campaign policy, staff access, promotional copy, and the receipts and orders flowing in from their own POS or Shopify connection. Customers control: their account, consent preferences, and wallet.

    • TLS everywhere; database encryption at rest
    • Least-privilege secrets, rotated regularly
    • No PHI stored — healthcare surfaces use appointment confirmation only

    Frequently asked

    Are you SOC 2 certified?+

    IncentivPay is not currently SOC 2 certified. Enterprise buyers with certification requirements can reach out at sales@incentivpay.com to discuss the roadmap.

    Where should I report a security issue?+

    Email security@incentivpay.com. We aim to respond within one business day.

    Do you sign DPAs?+

    Yes, for Enterprise engagements. Contact sales@incentivpay.com to start.

    Bring your security review.

    We'll answer your questionnaire against the controls currently enabled on the platform.