Security & trust
We built Microhired so we never have to hold your money.
The most important security property of a money platform is where the money is. Ours is simple: it's never with us.
How money moves
payer → Stripe → each party's bank
Bills are collected by Stripe on a Stripe-hosted invoice page. When a charge settles, Microhired instructs Stripe to transfer each party's share to their own Stripe account, and Stripe pays out to their bank. Funds never pass through a Microhired bank account: there is no escrow, no stored balance, no advance — by deliberate design, so your money is never exposed to us. What Microhired holds is the record: the locked agreement, the bills, and a double-entry ledger reconciled against Stripe, where every journal sums to zero and every disbursed bill ties back to its settled charge.
The payments partner
Payments, identity verification, and payouts are provided by Stripe, which is certified as a PCI DSS Level 1 service provider — the most stringent level. Your card and bank details are collected by Stripe directly and never touch or transit Microhired's servers; we cannot see them. Stripe performs the know-your-customer checks before a party can receive payouts, which is also why every recipient briefly meets Stripe during onboarding.
Your data
What we keep
Your name and email, the deals and agreements you sign (with their signature records — identity, timestamp, IP, and a fingerprint of the exact terms), bills, and the payout ledger. Executed agreements are retained permanently — that permanence is the product.
What we never see
Bank account numbers, card numbers, and government IDs go directly to Stripe. We run no advertising or analytics trackers — the only cookies are a session cookie and a security token. We don't sell data, full stop.
The complete picture, including subprocessors, is in the Privacy Policy.
How we run the platform
- Everything over TLS, with HTTPS enforced, strict transport security, and a restrictive content-security policy.
- Signed webhooks only: every Stripe event is signature-verified before it's processed; the app refuses to boot without its webhook secrets.
- No passwords to steal: sign-in is by single-use, expiring email links or Google/LinkedIn.
- Opaque identifiers: deals and documents are addressed by unguessable references, never sequential numbers.
- Locked agreements: accepted terms are immutable; any change creates a new version that every party must sign again.
- Pinned, patched dependencies and a nightly ledger-verification job that alerts if a single cent is out of place.
We're a small team and we'd rather be specific than grand: we don't yet hold a SOC 2 report, and we won't claim one until we do. The practices above are real, in production, and checkable.
What we are not
Microhired is a software company — not a bank, not a money transmitter, and not FDIC-insured. Funds in flight are held and moved by Stripe and its banking partners under Stripe's own terms and protections. If Microhired vanished tomorrow, your money would be exactly where it always is: in Stripe's rails or your bank account — and your executed agreements would still be in your inbox, because we email every party a copy at signing.
Report a concern
Found something that worries you? Write to hello@microhired.com with "security" in the subject line — a human reads it, and we'll acknowledge within two business days.
The safest place for your money is not with us.
1% per disbursed bill · Payouts by Stripe · We never hold your funds