TRUST @ PROPAY

Security at ProPay

ProPay is an AI claims automation platform for the home warranty industry. Warranty administrators trust ProPay with homeowner records, claims histories, and contractor data. This page documents how that data is protected, who can access it, and what independent auditors have verified.

SOC 2 Type II & Type I attested

Encrypted in transit and at rest

99.992% uptime SLA

Human review on every AI recommendation

01 / COMPLIANCE

Is ProPay SOC 2 compliant?

Yes. ProPay holds a SOC 2 Type II attestation. Type II means an independent auditor tested whether security controls operated effectively across an observation window, not merely that they existed on a single day. The full report is available to customers and prospects under NDA through the ProPay Trust Center.

How can I verify ProPay’s compliance status?

ProPay maintains a public Trust Center at trust.delve.co/propay showing live status across 79 monitored security controls. Control status is monitored continuously rather than reviewed annually, so the Trust Center reflects current posture rather than a point-in-time snapshot. Compliance reports, policies, and certificates can be requested directly from that page.

Which security policies does ProPay maintain?

ProPay maintains documented policies covering data protection and encryption, data classification, access control, incident response, business continuity and disaster recovery, vendor management, and change management. Each policy is version controlled and reviewed on a defined cycle. Individual policy documents are available on request through the Trust Center.

02 / DATA OWNERSHIP

Is my data isolated from other companies using ProPay?

Yes. ProPay uses a multi-tenant architecture with full data isolation. Each client’s data is completely walled off from every other partner on the platform. Data is never pooled, shared, or cross-accessed between accounts, and no client query can reach another client’s records. Isolation is enforced at the data layer rather than only in application logic.

Who owns the data ProPay processes?

You do. Your organization retains full ownership of all data processed through ProPay. ProPay acts as a processor, not a controller. Your data remains accessible to you in real time via API or pub/sub endpoint at any point, without submitting a request or waiting on an export queue. Ownership terms are set out in the Data Processing Agreement.

Can I export my data if we stop working with ProPay?

Yes. Because ProPay provides real-time access via API and pub/sub throughout the engagement, your data is continuously available to you rather than locked in and released at exit. On termination, ProPay provides a complete export in an agreed format and deletes remaining data according to the retention schedule in your agreement.

Where is ProPay data hosted?

ProPay publishes current hosting, infrastructure, and subprocessor information through the public Trust Center at trust.delve.co/propay. The Trust Center is the source of truth for vendors supporting hosting, communications, analytics, and other processing activities. Customers are notified in advance of material subprocessor changes.

03 / ACCESS CONTROL

Does ProPay support single sign-on?

Yes. ProPay supports enterprise single sign-on via the OIDC protocol and integrates with identity providers including Active Directory and Microsoft Entra. SSO allows your organization to enforce its own authentication policies, including MFA requirements and conditional access, and to deprovision ProPay access centrally when an employee leaves.

How are credentials and client secrets exchanged during setup?

ProPay exchanges client secrets through secure vaults such as CyberArk, never over email or chat. Secrets are transmitted through the customer’s preferred vault at integration and rotated according to the customer’s policy. No ProPay onboarding process requires a credential to be sent in plaintext through an unsecured channel.

Does ProPay support role-based access control?

Yes. Access in ProPay is segmented by team and function, so each user sees only what their role requires. Dispatch and parts-ordering teams, for example, operate under separate permission sets and separate application configurations. Reporting also supports role-based views at individual, manager, and executive level, so operational detail and aggregate performance data are separately scoped.

04 / ENCRYPTION

Is data encrypted in transit and at rest?

Yes. All data in transit is encrypted, and file exchanges use SFTP with securely exchanged encryption keys. Sensitive fields, including name and address, are encrypted at rest. This design meets enterprise security requirements without requiring customers to stand up separate restricted infrastructure or a segregated environment for sensitive fields.

How does ProPay treat personally identifiable information?

ProPay encrypts sensitive personal fields such as name and address at rest. Field combinations that carry elevated re-identification risk, for example address together with date of birth, are handled under additional access restriction. Standard encryption controls apply to all remaining fields. Access to personal data is scoped by role and logged.

05 / AI GOVERNANCE

Does ProPay use AI to make coverage or claims decisions?

No. AI in ProPay recommends, it never decides. Every AI-flagged item routes to a human operations team for final judgment, and human-in-the-loop review is built in wherever regulation requires it. Coverage determinations, denials, and claim outcomes are made by people. ProPay’s AI reduces the time a human spends reaching a decision rather than replacing the decision-maker.

How is ProPay’s AI activity monitored?

Every AI agent conversation runs through a real-time guardrails dashboard with pass and fail flagging, visible to clients at any time. Clients can inspect what the AI said, what it recommended, and whether it passed each guardrail, without filing a request. This transparency has been reviewed as part of a dedicated client AI security and architecture advisory process.

What happens if ProPay’s AI produces an incorrect recommendation?

An incorrect recommendation does not become an incorrect decision, because no AI output reaches a claimant without human review. Guardrail failures are flagged in real time on the client-visible dashboard, and flagged conversations are triaged by the ProPay operations team. Recurring failure patterns feed back into guardrail configuration and model evaluation.

06 / INTEGRATION SECURITY

How does ProPay integrate with existing claims systems?

ProPay’s preferred integration model is API-first, using defined data contracts and data dictionaries agreed before implementation begins. This gives both sides an explicit, reviewable specification of exactly which fields move between systems. Flat-file transfer over encrypted SFTP is available as a fallback for lower-complexity integrations or legacy systems without an API surface.

What data does ProPay actually need from my systems?

ProPay requests only the fields defined in the agreed data contract, scoped to what the automation requires. The data dictionary is produced during integration design and reviewed by your team before any connection is established. Fields outside the contract are not transmitted, and expanding scope requires an explicit contract change.

07 / RELIABILITY

What uptime does ProPay guarantee?

ProPay has agreed 99.992% uptime SLAs with enterprise clients. Infrastructure alerting operates on a 500 millisecond detection interval, so degradation is caught close to the moment it occurs rather than at the next monitoring cycle. Specific SLA terms, measurement methodology, and remedies are defined in each enterprise agreement.

How does ProPay handle outages and incidents?

ProPay maintains a documented incident response process covering detection, triage, customer notification, and post-incident review. Customers receive notification within the timeframe defined in their agreement, with updates through resolution. Incident records are retained for analysis, and lessons learned feed back into security and reliability controls.

08 / MESSAGING COMPLIANCE

Is ProPay’s messaging TCPA compliant?

Yes. ProPay’s messaging architecture is built for TCPA compliance. Service-related texts and emails are treated as informational rather than telemarketing communications, which is the correct classification for claims status updates and appointment coordination. Automated opt-out handling for STOP and START is built into the system, and SMS delivery respects quiet hours by zip code.

How does ProPay handle homeowner communication preferences?

Opt-out requests are processed automatically and immediately at the system level, without manual intervention or a service ticket. Quiet hours are enforced by zip code so that message timing reflects the recipient’s local time. Communication preference state travels with the claim record and is available to your team through the same API access as all other data.

09 / WORKING WITH PROPAY

Will I work with a different team after go-live?

No. ProPay keeps the same team from integration through production support. There is no handoff to a separate support organization once you reach production, so the people who designed your data contract and integration are the people who support it. This matters most during the first ninety days, when integration-specific context is hardest to transfer.

10 / VULNERABILITY DISCLOSURE

How do I report a security vulnerability in ProPay?

Email ops@pro-pay.ai with a description of the issue and reproduction steps. ProPay acknowledges reports within one business day and provides a remediation timeline after triage. ProPay does not pursue legal action against researchers who report vulnerabilities in good faith, avoid privacy violations and service degradation, and give reasonable time to remediate before disclosure.

11 / DOCUMENTATION REQUESTS

How do I request ProPay’s SOC 2 report or a DPA?

Request documentation through the ProPay Trust Center at trust.delve.co/propay. The SOC 2 Type II report, security policies, and Data Processing Agreement are available to customers and prospects, with NDA where required. Requests are typically fulfilled within one business day.

Enterprise-grade AI Claims Transformation

Need to report a security concern or incident? Contact ops@pro-pay.ai

ProPay AI, Inc · 2913 W. Eagle Ridge Loop, Cedar City, UT 84720, United States

Enterprise-grade AI Claims Transformation

Need to report a security concern or incident? Contact ops@pro-pay.ai

ProPay AI, Inc · 2913 W. Eagle Ridge Loop, Cedar City, UT 84720, United States

Enterprise-grade AI Claims Transformation

Need to report a security concern or incident? Contact ops@pro-pay.ai

ProPay AI, Inc · 2913 W. Eagle Ridge Loop, Cedar City, UT 84720, United States