Security & service integrity

Security without security theater.

PayStubCheck uses practical controls around document generation, payment processing, abuse prevention, and data retention. This page explains the controls we can describe publicly without exposing operational details that would make the service easier to abuse.

Built to be understandable, inspectable, and appropriately limited.

PayStubCheck documents and research are designed around clear scope, limited retention, source transparency, and explicit limits on what a generated record can establish.

Payments

Card data stays with Stripe

Checkout is handled through Stripe. PayStubCheck does not receive or store full payment-card numbers. Purchase records retain only the limited transaction information needed for delivery, support, and accounting.

Free generator

Automated abuse is actively challenged

The free generator uses Cloudflare Turnstile, request-rate controls, usage quotas, and pseudonymous security signals. These controls are intended to keep a genuinely free tier available without making an email address or shared IP address the only abuse signal.

Data minimization

Security logs avoid payroll contents

Free-generator security events use pseudonymous identifiers rather than storing the underlying email address or IP address in the event log, and the security telemetry does not include detailed payroll entries. Security events are configured to expire after a limited retention period.

Calculations

Final calculations are server-authoritative

For supported paid and free paystub flows, final calculation logic is performed or rechecked on the server rather than trusting browser-calculated totals alone. Unsupported scenarios are handled according to the limits of the relevant engine instead of being presented as independently verified payroll.

Transport

Production traffic uses HTTPS

PayStubCheck is served over HTTPS so information sent between your browser and the service is encrypted in transit. No internet service can promise absolute security, so the platform also limits what it retains and how long temporary records remain available.

Reporting

Security questions have a direct path

If you believe you found a security issue, do not include SSNs, payroll contents, passwords, card data, or other sensitive material in an initial report. Contact support@paystubcheck.com with the affected URL and a concise description.

Want to understand what happens to your data?

See the separate data-handling page for the lifecycle of form inputs, temporary checkout data, generated PDFs, email delivery, and security records.

View data handling