Security

One of the most important considerations in providing our services at PayRange is security, so we have developed and operate an industry-leading security infrastructure.

PCI Compliance
PayRange’s systems and processes are designed to comply with the Payment Card Industry (PCI) Data Security Standards. Further, the service provider(s) of PayRange have been audited by a PCI-certified auditor, and is certified to PCI Service Provider Level 1, the most stringent level of certification available. For any questions or concerns regarding our payment service provider, you may contact them at support@stripe.com.

SSL and HSTS
PayRange forces HTTPS for all services, including our public website. We use 256-bit encryption for the mobile app and between 128 and 256-bit encryption, depending on your browser, for our public website ensuring that all communications are secure. We perform regular audits of certificates we use, the certificate authorities we use, and the ciphers we support.

In addition to using HTTPS we strictly use HSTS to ensure browsers interact with PayRange only over HTTPS and never a non-secure connection.

Encryption
PayRange supports encryption through all steps of a transaction.  Our service provider encrypts the Card Data at the first step of the card transaction and sends it directly to their servers. Please visit www.stripe.com/security for more information. PayRange servers are located in secure data centers and physical access is monitored by security personnel 24 hours a day and requires multiple levels of authentication.

Card Data
The PayRange app does not view, pass through, or store Card Data, and Card Data is never sent to or stored on PayRange servers. PayRange does not store any personally identifiable card data on our servers. We store the last four digits of the Card Data along with a token issued by our Service Provider(s).

Disclosure
We rapidly investigate all reported security issues. If you believe you’ve discovered a bug in PayRange’s security, please contact us at security@payrange.com. We will respond as quickly as possible to your report. We request that you not publicly disclose the issue until it has been addressed by PayRange.

Security Issues
For urgent security concerns or requests such as an incident, or suspected misuse of your account, please email our 24/7 priority security team at security@payrange.com. Please use our PGP public key so that your message is safeguarded. In your message, let us know how to contact you securely as well. Urgent requests will be addressed in 24 hours or less.

For non-urgent security questions, please contact support@payrange.com.

Our PGP key is below, which PayRange will use to sign all secure emails.

Learn about PGP.

Key ID: DFC238BD
Key type: RSA
Length: 2048
Fingerprint: 402C A1D4 C579 79F5 5DE4 4432 CD41 20CD DFC2 38BD

—–BEGIN PGP PUBLIC KEY BLOCK—–

mQINBF2x69sBEACw+oQWDOC6pFl3njex57LHDxWaANHe25sUM+/lHTGJNhkfpzi3
K3DFq1WmmtkL6MPH6zJu831gCdNoZ7diQ1EI8FijhIJv+buNyBTwuT0EaznmGMvI
/l4GDxU3PsBMr1nNdHJ8U5NSiBoo7sB2dcAD4jIcQZAtk9Y0uesH8cpY+npCW+wp
x2fUAOCfMutsWpTNTlmryDrG9nMHUWVZ3DKePX+QPZEqsPh5fxVdnLpgCm7tIIQF
91SUDXp1l5Ei1UInTtTyCdZa3xL53FZgn01ApSABNmVM7fnikgUZoPTXFbSFZMzk
wB6j7BjDcpdYAZZb7FmD6osxvkshzM87Dso3vgVSxb4SXFYT9UwEPe+OEqj0xg0M
eA1xmSWAEiGSLklSr+vYBWh2GNEvsnyP27JBA1YH/bk8Wpyw9Zj+evlT94kGE4nl
80++OSbWA9grb0hp7Du9T7Al6WQ81J9t4OKwf88oWRf+tcATOMZdMWv21UNMOZ1N
GGu7ESdBnsKowpACB1EO81MJ0285Xv9G2iQ/EMcIgrIePKgY05f7plmW73hVEZYb
Gxh4psKbx+rxshkVcyppFb4Tx5wLtzQRmVCawRmLICeI07y4Nc/tmI8M6JtE09pG
lzz+7ijyOJdt6hjZhMVW976pXZmjtrAr5GWMMBnqHhuCHWiV4xdjZEiPGQARAQAB
tCVQYXlSYW5nZSBJbmMuIDxzZWN1cml0eUBwYXlyYW5nZS5jb20+iQJOBBMBCgA4
FiEEbaKDom2tx15DHFENQU6duqL3thsFAl2x69sCGwMFCwkIBwMFFQoJCAsFFgID
AQACHgECF4AACgkQQU6duqL3thsjmg//QaOT1PlI/JI34zJtMD7+L9eLqbEC9YUv
thai1yiHBHDKupzzBXGge4wWuN4IirLYHI9xhObBa3lDXOwDC7Hhvr2ZQKYlb2QI
0Hxo3Fev2/GqQ/f34B8KU97u6uCecNp7I+Vx0ajePZQbTFt4tF0p7dIJjV1lgaDA
oRT32rPqWYDvP0AtUGa3yw2mAsnOYX9z7I2R30xrJSo9FzwTfvIAlXDow+rpmLGI
I9z9jy16PqDmlpW1iAEklC6cgiJUxDM8WJOy3syPI4Znolb173iO9Eg8OPyzHqFC
kmaveR4OqyY/8Vm0RO3+N/GKVjNROz2HIAUvDxY0Tws3M0sFs0AJfvT4kxz0VEAh
A+EP0hpxomoSyGSWvsQ0IsX3qmjgTC/kzCUBKqANWKA3nuzAbDi0WzIYnXrhusRq
gulXAAkf7WPuKhz5mg3+uHMMDvz+BqA7o3QfkZlkREQo/Kb68zyTFf0dUiVMcLXm
5PpTpsbK4eENUs/SZL6wei021jJv/Lgi9Ac6q/Dx/veeN6c8YLAUAV9L0+aJVwyL
+Vaj+euish6FSV62jwEsthjY64STbqyTAH7khcwjM+Oee5m+9yMhNxp13u2aDJwj
euEtX+tJMab0FTjR5RhqXVr0/Fr8jywWf69M3bsb0RIFrSYwd+AJ/+Edz50yKglr
VbF+V0priyq5Ag0EXbHr2wEQAOZLNu/+zQxe3hWo9wmmmYMIhJH4wAtOO5A2iTA9
vOfUzI1iZ6Mls7GVavRe+fQOq1m1jVk6n0XHcIqxUrjH0N94c8smg1S1kXyKWMGn
so7vtw+dNMquydkigP69cCoEbAi2VCMCsJ5xcvEIHN8HrrGcCtFDN6vSnlmQutYa
CQTxiRmgKUKYeFTPlG1QektkjYtNNuZxiNPHSrdWBrl8xPC6XgThfUU7fXDnAx9e
MGHPDiyUUQ6MGt3VOXvsRlEhsHh4g25Me2m4V8mUnUI0R4dvzyrWIGiVTlSBtN+c
acAgiEogtaVIeFcC+5vLXlQbtEDaZ47dJi4fkMTb+C96chCDkbPmZdJBJCqnSbJx
wEvjbw8E48gr5ktpcyf1Ls6P1A/Ty0KU6Sw765viMXrgKjFqontEepW+TGJiw8Ac
aZxE36TnVUl7ZnN75etCJtLGthrPFE8KtwUndGIwlyvdjokYrNZ9G3sanYciZNKO
fZRzASfB21t/ODxXLBxnA5oHWq44SqHBwagcs3o+0Rro6x1kc70ND3f04N2QtEAG
TF6wuXTgO1miChJRDY8GWU+H2BGx02auk3HrehYu1PmFq5TmEUPw0yLYfVATUhWH
ZHCt5Lh7QiQ8IUC//+RNRpxntlES+PBZoP3nJmp+bK46bH/5p8uVvSqAlJYJYiVH
4/9RABEBAAGJAjYEGAEKACAWIQRtooOiba3HXkMcUQ1BTp26ove2GwUCXbHr2wIb
DAAKCRBBTp26ove2G5YoD/9/SxBsXHSyogp/2xL+8gDbn9sQ0OGfmB8HQzelar79
KXa628C23rJ4WZ1mzzzMC/H8uYqo9EjyO6DKJMj2HIYEOyxWmm4UNR3n5ftUMSai
QlW6j3XHbhILqFLg34a7AMmjOR1iIDOz6vozcAJ+lHDGP2v9QI65gCiEojQvNL5+
vhRUSg4WEPhJc0jk2WJtUjdup74R1BvLaL96M6QUAlYS3jXY+eoQLQM4dUkgCeOz
4/WLjGs/ZiMq6GtchaWGx+RUuqCqcOofpK3pDmdqiq8fPyb2+Ri1wif424IK+V50
UHB5NiMWqgjS8BDqZIsPaHhygr7PCQ14YqkYleiZzd2ETipABAix2WduqjEMK/Vz
BNJtNUl05Zf5oOkulQbf0TyRAymq8h+ZN44XrEcTMgLls4ROxZRPW5xtz6egcXMl
mA5fLc/EG8oupAVnXMgSkBnMVRjeaHzW9tG//x0OOMtwW4HezxwfRPqA0FBebWoj
5VLexfaOV7vSYkJ9ar1rcAvYvYYoDhE9iABvZgG3drsSJlbIyEw9n0+NRYTGq/pr
NtrAEkGoISSTTb0dJLLtZuwzHrT0cUTrZjEhlLxce0zZuqZAM+AziMpQmXg25L5j
2LNBcpmJl1Leqkqx5mVPQgMWvZgRlJygn7ByL+xzT/GGw+11bMuxSrtvAs3e/pBW
dg==
=oeCu
—–END PGP PUBLIC KEY BLOCK—–


 

October 2019
v1.1