Security and privacy

Learn how PayCanvas separates payroll accounts, protects credentials and evidence, and limits what connected assistants can see.

PayCanvas treats payroll and its supporting evidence as private to each payroll account. Public support content and product diagnostics must never contain real employee identities, compensation values, private mappings, passwords, original provider responses, reports, or identifiable payroll results.

Prerequisites

  • Use your own PayCanvas account; do not share credentials.
  • Verify the payroll account name before reviewing or changing payroll data.
  • Use MFA when connecting an MCP client.
  • Keep original payroll files only in approved, account-specific storage and workflows.

How access is scoped

  • Every record belongs to one payroll account, and access follows your active membership in that account.
  • PayCanvas checks account boundaries in both the application and database so sources, mappings, and calculations cannot be linked across accounts.
  • Authorized payroll operators can perform the limited changes exposed by the workspace; other members receive role-appropriate read access.

How credentials and evidence are handled

  • Provider passwords and keys are stored securely on the server and are not displayed after saving.
  • PayCanvas connects only to approved provider addresses and uses limited, configured collection workflows.
  • Raw reports and original provider responses remain private to the payroll account.
  • Configuration candidates are versioned and stored encrypted at rest.
  • Calculations retain safe references and cleaned evidence needed to explain a result and reproduce it from the same inputs. Technical hashes confirm which versions were used.

MCP privacy boundary

The payroll connector requires secure PayCanvas sign-in, active account membership, and a six-digit authenticator code. Access is tied to the exact client and is checked again whenever it is used.

MCP tools return only authorized summaries, payroll lines, decisions, safe audit details, references, and cleaned source descriptions. They omit passwords, raw report contents, original provider responses and identifiers, private mappings and aliases, unrestricted source rows, and platform-only settings.

The public connector must not be used to request or send Social Security or other government identifiers, bank or routing information, payment-card data, health or benefits information, passwords, API keys, access tokens, authorization codes, MFA codes, raw provider credentials, or raw provider payloads. PayCanvas checks public MCP inputs and responses for these restricted categories and blocks a response instead of returning a detected restricted field or labeled value.

Internal IDs, timestamps, and hashes appear only where the assistant needs them to select the exact tenant-scoped record, order payroll history, prove immutable lineage, prevent stale writes, or produce an idempotent audit receipt. The assistant should keep opaque values internal unless a technical reviewer specifically asks for them.

Report a suspected exposure

  1. Stop sharing or downloading the affected material.
  2. Disconnect the involved MCP client if applicable.
  3. Record the payroll account, approximate time, screen or action, and safe error/reference code.
  4. Contact PayCanvas Support without attaching raw payroll files or credentials.

Expected result

Users and connected clients can access only the payroll accounts and fields authorized for their role, while sensitive source material remains behind the account-private server boundary.

Troubleshooting

  • Data from an unexpected account appears: stop immediately, do not copy it, and contact support as a security issue.
  • MCP returns invalid_token: reconnect through OAuth; never paste a browser or bearer token into configuration.
  • A credential may be exposed: revoke or rotate it through the approved platform process and contact support.
  • Need to share evidence with support: send sanitized references and error codes first; wait for an approved secure transfer path.
SOLVING THIS WITH CHATGPT?

Share this article URL and describe what happened.

Include the step you are on, what you expected, and a safe error code. Do not share employee pay, raw reports, credentials, MFA codes, or access tokens.