Security
Built to keep your billing data yours
MetroPay keeps each workspace's data apart, offers a second factor for sign-in, and never touches the money your customers pay you. This page lists what is in place today, and what we do not claim.
In place today
What protects your workspace
Each card describes a mechanism that exists in the product. Nothing here is a plan or an intention.
Role-based access
Owner, Admin, Accountant and Staff. Staff can create and send but cannot record payments, void, write off or change settings.
IncludedTwo-factor and passkeys
Authenticator-app codes and passkeys, both set up behind a password confirmation.
IncludedEmailed login codes and password step-up
Sign in with a one-time emailed code if you prefer; sensitive settings ask for your password again first.
IncludedPer-workspace isolation
Every record is scoped to its workspace at the data layer, so a link to another business's data answers with not found.
IncludedSigned links for documents
PDF renders, estimate decisions and unsubscribe links are authenticated by a signature in the link, not by a session.
IncludedEncrypted gateway credentials
Provider credentials are stored encrypted and are never returned to the browser.
IncludedAudit trail of settings changes
Who changed which setting and when, recorded by field name, never by value.
IncludedRate limits on public pages
Invoice, payment and sign-in pages are throttled per address, so a leaked link cannot be hammered.
IncludedPayments through your own account
Card details go straight to Stripe or SSLCommerz under your own agreement with them. They never touch MetroPay.
Included
Access
Four roles, and one rule about money
Owner, Admin, Accountant and Staff. Staff can create, edit and send invoices but cannot record payments, apply credit, void, write off or change settings. Only owners and admins change settings, invite members or connect a payment account.
- A second password check before a domain is added, a workspace is reset or a deposit is resolved
- Owners can preview the workspace as any role before handing it to someone
- Settings changes are logged by field name, never by value
Your domain
Your own domain, with a certificate we issue and renew
When you serve public invoice and payment pages from your own subdomain, ownership is proved with a DNS record you publish, and the certificate is issued and renewed at the edge without you handling it. Until both are in place, pages keep being served from MetroPay.
- Verified by DNS before a single page is served from your hostname
- The workspace is resolved from the document, never from the address bar
- Adding or removing a domain asks for your password again
Plainly
What we do not claim
A short list, kept current. If something you need is on it, ask us rather than assume.
- We do not currently hold an independent security certification or audit report. If your procurement process needs one, ask us before you commit.
- We do not currently offer a self-service backup or bulk export. If you need a copy of your data, write to [email protected].
- We do not currently support single sign-on or IP allow-listing. Two-factor and passkeys are available to every account.
- We do not currently publish a status page.
MetroPay runs on DigitalOcean in Bangalore, India. Email goes out through Postmark, and card payments run through Stripe or SSLCommerz in your own account. The Privacy Policy says what is stored and for how long, and the Sub-processors list names every provider that handles data on our behalf.
Maintained by Product owner, Studio Metrodesk, IncReviewed Next review
Questions about security
Ask us anything on this page
If your accountant, your client or your own checklist needs a detail that is not here, write to us. You will get an answer from a person, and the page will be updated if it should have said so.