Security and compliance

We move your money. Here is how we protect it.

This page states what is in place today. Where something is planned rather than live, it says so. Your accountant and your indemnity insurer are welcome to read it.

Encryption

Data is encrypted in transit with TLS and at rest in the database and in backups. Keys are managed by the cloud provider's key service, not by us.

Australian hosting

Application and database run in Australian cloud regions. Backups stay in Australia.

Individual logins

Every user has their own account with multi factor authentication. Shared logins are not supported by design.

Role based access

Practice managers, owners, accountants and practitioners each see only what their role needs. A group administrator sees across sites, a practice manager does not.

Read only clinical access

The connection to your practice management system can read billing data and nothing else. It cannot write, edit or delete.

Immutable audit log

Approvals, agreement changes and payment events are recorded with user and timestamp and cannot be edited or removed.

Payment authorisation

Funds move against PayTo mandates authorised by the practitioner in their own bank. A pending or revoked mandate holds the payment.

Independent penetration test

Planned

An external test of the platform is scheduled, with the summary report made available to customers under NDA.

Formal certification

Planned

We do not hold ISO 27001 or SOC 2 today and will not claim otherwise. The control set is being documented against those frameworks.

What 2PAY never does

Write anything back into your clinical system. Access is read only.Store clinical notes or diagnoses. Only what is needed to bill and pay.Move funds without an approval recorded against a named user.Sell, share or use your data to train anything.

Ask for the detail

We keep a security overview, a data flow description and a subprocessor list ready for procurement and insurance reviews. Ask and we will send them.

Request the security pack