Financial application security and operations.
How we protect the platform.
Platform ownership
Outpave maintains the application platform and manages its security, data storage, and platform compliance.
Program responsibilities
Your issuing and payment providers set the requirements for their services. We work with your team to define onboarding and operational responsibilities.
Customer access
We scope the roles, permissions, and approval workflows your users and operations team need.
Disputes and servicing
Outpave handles disputes and services the platform, with second-line support for your team.
Your customer relationship
You own the first-line support experience. We support your team when a question needs platform expertise.
SOC 2 ready
We are SOC 2 ready and working through the assessment process. Contact our team for the current status and available security documentation.
Documents and policies.
Website & Mobile App Terms
The terms that govern your use of the Outpave website and mobile apps.
OpenUser Terms
The agreement between Outpave and each User or Administrator on a company’s Outpave Account.
OpenAccount Linking Terms
The terms for linking an external bank or card account to the Services.
OpenCard Program Terms
Credit terms, repayment, and defined terms for the card program.
OpenPlatform Agreement
The issuing bank terms a company accepts to open an account and use the Services.
OpenPrivacy Policy
What information we collect, why we process it, and the rights you have over it.
OpenEvery document above is published in the legal library. Ask us for our security overview during scope.
Questions we get in every review.
Where is customer data stored?
Outpave maintains the application platform and manages its data storage. We confirm where your program's data is held, and for how long, during scoping, and record it in the platform agreement.
Are you SOC 2 certified?
We are SOC 2 ready and working through the assessment process. Ask our team for the current status and the security documentation available today.
Who handles a dispute?
Outpave handles disputes and services the platform. Your issuing or payment provider adjudicates on its own network, and your team owns the first-line conversation with the customer.
How are roles and permissions scoped?
Per program. We scope the roles, permissions and approval workflows your users and operations team need before launch, and every action is an entry before it is a screen.
How do I report a vulnerability?
Write to security@outpave.com with the detail you have. We acknowledge a report within one business day and tell you what happens next.
Have a security question?
Bring it to the first conversation. We would rather answer it before you sign than after.