PayEm follows a structured yet flexible onboarding approach tailored to each client’s needs. The typical steps include:
Initial Discovery & Planning After a demo and notice of interest, PayEm’s Team assesses your organization’s ERP, HRIS, approval hierarchies, spend policies, and specific workflows. This forms the foundation of your implementation plan.
Vendor & Request Form Setup Through the Vendor Onboarding interface, users customize intake forms, define approval rules, and upload documentation. Data is validated and pushed into your ERP system via real-time sync.
Approval Flow Configuration Using Agile Workflows, you design scalable, no-code, multi-level approval processes driven by HRIS data and ERP budgets. Slack/email alerts can be enabled during setup.
Card Issuance & Finance Integration Virtual and physical cards are activated with spend controls. The system is linked to your chart of accounts, PO numbering, cost centers, and user permissions—either tied to vendor requests or request forms.
Invoice OCR & Matching Invoice Processing setup includes training the OCR/ML engine to recognize invoice formats, enabling rules like duplicate suppression and PO-reconciliation. Tests are run against a pilot data set.
ERP & HRIS Sync Activation PayEm connects with your ERP (NetSuite, QuickBooks) for transaction syncing, chart configuration, and PO matching. HRIS integration populates reporting lines and approval chains automatically.
Testing & Training Pilot users validate workflows end-to-end—submit requests, card transactions, invoices—identify exceptions, and finalize mappings. Stakeholder training ensures readiness for full rollout.
Full Rollout & Go-Live With testing confirmed, all employees are onboarded, global payments enabled, and approval chains enforced organization-wide. Acknowledgment via email or Slack notifications signals launch.
While PayEm doesn’t state a formal timeline, general ERP onboarding benchmarks are 60–90 days, depending on complexity. With PayEm’s no-code forms, real-time integrations, and vendor support, many clients expect turnaround on the faster end, especially when ERP and HRIS are already structured.
Customisation
PayEm offers extensive adaptability to fit specific business needs, with multiple customization layers:
No-Code Request Form Builder Users configure multi-purpose intake forms for different requests—SaaS subscriptions, employee travel, vendor onboarding—adding required fields, conditional logic, and templates without developer support.
Dynamic, Role-Based Approval Workflows Approval chains are defined with hierarchical data from HRIS, featuring dollar limits, conditional routing, multi-tier sign-offs, and PO/receipt workflows. Configurable via UI, no technical setup needed.
Corporate Card Controls Issuance of cards with granular settings—per merchant, duration, department, or tied to specific requests and dynamically cancelled via HRIS events.
ERP Integration & GL Mapping Deep configurations for amortization, expense categories, segments, intercompany workflows, and PO line matching. Supports bi-directional sync and invoice posting—avoiding manual reconciliations.
AI-Driven Invoice Customization OCR auto-maps GL codes and amounts but allows manual overrides when needed. Duplicate suppression threshold, line-item logic, and match tolerances can be configured.
Integration Ecosystem Popular integrations with BambooHR/HiBob, Slack, Okta/Azure AD—each connected via UI, no custom coding.
Custom Permissions & Audit Logs Role-based access settings ensure control. Every transaction is timestamped, logged, and traceable with configurable visibility filters.
Templates & Use-Case Adaptability Pre-built templates for common workflows—SaaS subscriptions, equipment purchases, sales agent reimbursements—reduce setup time and improve governance.
PayEm focuses on enabling business-owned configuration, meaning finance teams can continuously iterate on forms, limits, routing logic, and integrations—without depending on IT or support tickets.
Training
Onboarding & Training
Self-service configuration: Users build request forms, approval workflows, and vendor onboarding with complete control—no coding required.
ERP/HRIS integration assistance: PayEm guides the mapping of GL accounts, budgets, employees, and hierarchies during initial setup.
Pilot & training: Client-facing setup includes testing scenarios—POs, card usage, invoices—followed by stakeholder training before rollout (industry-typical).
Security and compliance support is available via dedicated email addresses.
SafeBase/Trusted Security Portal (~ISO, SOC 2) provides access to audit reports and documentation for due diligence.
Community & ticketing: No public forum or 24×7 phone line advertised, but reviews cite fast in-app/email responses and personal onboarding.
Security Measures
PayEm maintains an advanced enterprise-grade security posture:
Access Control & Authentication
MFA required for all users, plus SAML SSO (Google, Okta, Azure).
Least privilege model with comprehensive audit logging for all user actions.
Encryption & Infrastructure
TLS/HTTPS encryption in transit and AES-256+ at rest, plus in-field encryption of sensitive data.
Hosted on major cloud providers, with redundant backups and RPO of 24–48 hours.
Endpoint security, DNS filtering, DDoS/firewall protection, and internal code security processes (credential management, code review).
Compliance & Auditing
Annual SOC 1 Type II & SOC 2 Type II audits conducted by Ernst & Young.
ISO/IEC 27001, PCI DSS, GDPR, and CCPA compliance confirmed via the SafeBase portal.
Penetration Testing & Vulnerability Management
Ongoing automatic penetration testing and rate limiting to defend against brute-force attacks and DDoS.
Only trusted third-party vendors with equivalent security practices are permitted.
Policy Transparency
Uploadable Security/DPA/Master Services Agreements, publicly available on the SafeBase portal.
Annual scans with 3rd-party testing firm; no exceptions reported.
Updates
PayEm operates as a cloud-based SaaS platform, so updates are continuous and managed automatically. Customers do not need to install patches or manually upgrade. Feature enhancements, bug fixes, and security updates are deployed seamlessly in the background, ensuring minimal disruption. Based on industry norms and user feedback, PayEm pushes regular incremental updates (often monthly or quarterly for major features) and uses in-app notifications and release notes to inform users of changes. This approach guarantees that all clients run on the latest version without extra IT overhead.
Data Ownership and Portability
PayEm’s policy aligns with standard SaaS practices:
Customer owns all data uploaded or generated within the platform (invoices, transactions, approvals, etc.).
PayEm acts as a data processor, not the owner, under GDPR and CCPA compliance frameworks.
Data portability is supported through export options (CSV, ERP sync, API access), allowing organizations to retrieve their data at any time.
Upon contract termination, PayEm provides a data export window before securely deleting data from its servers, following SOC 2 and ISO 27001 protocols.
Scaling Up / Down
PayEm offers flexible, usage-based scaling:
Adding new users, subsidiaries, or payment volume can be done instantly via the admin dashboard.
Pricing adjusts based on active seats, transaction volume, and feature tiers—so scaling up typically means higher subscription or transaction fees.
Scaling down (removing users or reducing volume) is allowed, but usually requires notice aligned with contract terms (often 30–60 days for enterprise agreements).
PayEm’s architecture supports multi-entity and global operations, so expansion across regions or currencies does not require a new platform instance—just configuration changes.
The terms & conditions for contract renewal and cancellation
1. Automatic Renewal (Evergreen Clause)
PayEm’s June 2025 General Terms of Service include an automatic renewal clause: contracts renew for additional terms unless terminated within a specified notice period.
This follows standard SaaS practice: if not proactively cancelled, the contract continues under its original terms.
2. Notice Period & Termination Rights
While PayEm’s T&Cs define this evergreen renewal, they do not publicly specify the exact notice window (typically 30–60 days written notice required before renewal date).
Standard clauses allow PayEm or the customer to terminate “for cause” with notice if the other party breaches key obligations—such as non-payment, misuse, or confidentiality violations.
3. Cancellation Process
Customers should formally notice cancellation in writing per the agreement. If notice isn’t given within the required timeframe, the contract automatically renews.
After termination, services continue until the end of the paid term, and PayEm typically allows a grace period for data export, followed by secure deletion per their Privacy Policy.
4. Pricing & Automatic Increases
Renewal may include updated pricing or revised policies, provided customers receive advance notice—common in SaaS agreements.
5. Best Practices Mentioned
Clients are recommended to implement contract tracking to avoid missed notice windows. Clear terms about auto-renewals and cancellation deadlines should be negotiated in advance.
Compliance
PayEm adheres to stringent data protection and financial compliance protocols:
1. SOC 1 Type II & SOC 2 Type II
SOC 1 attestation covers internal controls related to finance (e.g., fund requests, PO, card management, bill payments).
SOC 2 confirms rigorous standards for security, confidentiality, and availability, audited annually by EY.
2. ISO 27001 & PCI DSS
PayEm is compliant with ISO/IEC 27001 for enterprise-ready information security management.
Its integration with banking services requires PCI DSS compliance; this is confirmed under its Security & Compliance documentation.
3. GDPR & CCPA (Privacy Laws)
PayEm’s systems are GDPR-compliant with individual rights support, and they integrate CCPA standards for California residents.
4. Penetration Testing & Security Standards
Continuous automated penetration testing, DDoS protection, rate limiting, and access controls like MFA and SSO are published in their compliance overview.
5. Data Privacy & Due Diligence Transparency
PayEm’s Privacy Notice (Nov 2024) outlines how personal data is processed, retained, and deleted.
The company uses tools like SafeBase to provide customers with access to audit reports and certifications.