Melio publishes security and assurance information worth reviewing. Public statements cannot guarantee an individual payment is safe, and we have not audited the platform or reviewed its private reports.
What Melio publicly states
On its security page, Melio describes an annual SOC 2 Type II audit, ISO/IEC 27001, 27017, and 27018 certifications, multi-factor authentication, and encryption. It also says a third-party Level 1 PCI-compliant processor handles sensitive card information. These are provider statements, not independent findings from Payables Guide.
A SOC 2 report concerns controls within a defined scope and period. It is not a guarantee against fraud or loss. For a material vendor assessment, request the relevant report and scope through the provider's available process and have a qualified reviewer evaluate them. Do not infer details from a badge alone.
Three questions a security badge cannot answer
| Question | Evidence needed |
|---|---|
| Is this a legitimate invoice? | Approved purchase, completed work, vendor relationship, and duplicate checks. |
| Is this the correct destination? | Verified payee details and a trusted process for changes. |
| Should this person release funds? | Documented authority, appropriate access, and approval history. |
A secure platform can faithfully execute an instruction that your business should never have approved. The control objective is to reduce the chance that a compromised inbox, a mistaken invoice, or excessive access becomes an authorized payment.
Give each person the access they need
Use individual accounts and enable the available authentication protections. Decide who can add vendors, edit payment details, approve invoices, release payments, and administer users. Review that access when a person changes roles or leaves. An external bookkeeper may need accounting visibility without unrestricted authority to move money.
Where practical, separate preparation from release. For a very small business that cannot maintain two people for every step, add a deliberate review of new vendors and unusual payments before authorization. Keep the review record. A shared password removes useful accountability and makes it harder to investigate who changed an instruction.
Treat changed bank details as a separate event
The FBI recommends verifying changes to payment procedures or account numbers. Contact the vendor through a previously trusted channel. Do not rely only on a reply to the email requesting the change or on a phone number included in it.
Consider an illustrative invoice that looks identical to last month's except for new bank details and an urgent note. The invoice amount may be legitimate while the payment destination is fraudulent. Pause the change, verify it, and record who confirmed it. The correct response is not to test the suspicious destination with a smaller payment.
Review the status after approval
Keep an exception list for payments that are held, returned, canceled, or not matched by the vendor. Someone should own that list before the next payment run. A bank debit can occur before the supplier receives funds; a scheduled payment can still fail. Do not close an investigation on the strength of a single status label.
Retain the invoice, approval, payment reference, and communications. If an approver changes the amount or destination after review, determine whether another approval is required. Ask the provider to demonstrate the applicable behavior in your plan rather than assuming all changes trigger the same protection.
Have an incident response path ready
If you suspect a fraudulent or incorrect payment, contact the payment provider and relevant financial institution immediately through official channels. Ask about cancellation, recall, or recovery options without assuming recovery is possible. Preserve the original messages and transaction references for the investigation.
Limit further unauthorized access while coordinating with your administrator, and report suspected business email compromise through the appropriate official reporting route. After the immediate response, identify which control failed and change the process. The purpose is to prevent recurrence, not merely to recover one payment.
A practical assessment conclusion
The public information provides a starting point for vendor due diligence, not a universal safety verdict. For your business, combine the provider documentation with a review of permissions, vendor verification, payment approval, and exception handling. Revisit the assessment when your team, payment volume, or integration setup changes.
For operational guidance, see contractor payments and payment-method selection. Those workflows put the internal controls in context.
The evidence
Sources & review notes
Public documentation reviewed September 4, 2026. Fit assessments are editorial judgments; worked scenarios are illustrative. We have not conducted a hands-on provider benchmark. Fees and availability can change.
Suggest a correction