\t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t \t \t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \t \t\t \t \x3c!-- Generator: Adobe Illustrator 29.1.0, SVG Export Plug-In . SVG Version: 2.1.0 Build 142) --\x3e Download-GooglePlay \t \t\t \t\t \t\t \t\t \t\t \t \t \t \t \t \t \t \t navigation-down-circle
Information Security

Vulnerability Disclosure

Collaborating with the global security research community to identify, remediate, and safeguard customer data.

As a part of our continuing focus on the security of our customers and data, Paylocity is proud to work with the information security community to promptly identify and address software vulnerabilities.

We recognize the critical role independent security researchers play in Internet security. If you believe you have discovered a vulnerability in a Paylocity application, service, or infrastructure component, we appreciate your cooperation in responsibly disclosing it to us.

How to Report a Vulnerability

Please email your vulnerability findings to our Security Operations Center at security@paylocity.com.

Please include the following details to help us triage and investigate efficiently:

  • A detailed description of the potential vulnerability and its estimated severity;
  • Step-by-step reproduction instructions or a minimal proof of concept (PoC);
  • Affected URLs, API endpoints, HTTP request/response samples, or parameters; and
  • Any defensive mitigations or recommendations you suggest.

Responsible Research Guidelines (Safe Harbor)

When conducting security testing, researchers must act in good faith and avoid violating laws or compromising user privacy:

  • Do not harm: Do not degrade platform availability, disrupt service, or execute Denial of Service (DoS/DDoS) attacks;
  • Protect privacy: Do not view, alter, exfiltrate, or delete customer data or PII;
  • No social engineering: Do not engage in phishing, physical attacks, or social engineering against Paylocity employees, partners, or clients;
  • Coordinated disclosure: Allow Paylocity reasonable time to remediate the vulnerability before public disclosure.

Our Commitment to You

We acknowledge receipt of valid reports promptly (typically within 2 business days), maintain an open dialogue during investigation, and will not pursue legal action against researchers who comply with our safe harbor guidelines.

Looking for Customer Security & Compliance Details?

To review Paylocity's SOC 1, SOC 2 Type II, ISO 27001 certifications, data encryption standards, and continuous disaster recovery safeguards, visit our security portal:

Visit Protecting Our Clients Hub →

Demo our unified platform

See how enterprise-grade security and modern HR technology empower your organization.

Request a Demo