ACH Security FAQ

Systems operating normally

How we protect your payment information

Straight answers about how ACH payments through Hollow & Company are transmitted, verified, and stored — and why we deliberately don't keep on file.

SECURITY SNAPSHOT
encrypted in transit

No physical document

Payments are submitted and transmitted electronically — there's no check to intercept, wash, or alter.

verified in real time

7,693 institutions checked

Routing and account details are validated against the Federal Reserve's directory before anything is submitted.

not stored electronically

Your data isn't kept on our servers

Form data is passed directly to our payment processor and is never saved on our internal systems.

one-time authorization

You control every payment

Each submission authorizes a single ACH debit — never a standing or recurring authorization.

Your payment
Is using the ACH payment form safe?+

Yes. When you submit a payment, your information is encrypted in transit and sent directly to our payment processor — the same category of transmission used across mainstream electronic banking. There's no mailed document in the process at all, which removes the specific risk this page exists to address: mail theft and check washing.

Does submitting a payment give you ongoing access to my account?+

No. Our system is built around a one-time-use model. Submitting the form authorizes a single ACH debit for the amount you specify — not a recurring or standing authorization. If you want to make another payment later, you'll submit a new request.

How do you verify my routing and account number?+

As you enter your payment details, our systems check the routing number in real time against the Federal Reserve's directory of 7,693 U.S. financial institutions. This catches typos and invalid routing numbers before a payment is ever submitted, reducing the chance of a failed or misdirected transaction.

Will I ever be charged a fee for using ACH?+

No. A number of businesses now charge a "convenience fee" for electronic payments — we don't, and we won't. Using our ACH option is, and will remain, free.

Your data
Do you store my banking information?+

Not electronically. Once you submit the form, your data is passed through a secure internal process to our payment processor — it is never written to a database or file on our internal servers. There's no electronic record for someone to breach, because there isn't one to find.

If nothing is stored electronically, what record exists of my payment?+

The only footprint of a transaction is a single physical, printed copy, generated once per day and stored in a locked file cabinet with restricted access. It's retained only for as long as we're legally and contractually required to keep it to meet our payment processor's regulatory obligations.

What happens to that physical record afterward?+

Once the required retention period ends, the document is destroyed by cross-cut shredding to a P-5 security level — a shred size of 30 mm² or smaller, the standard used for highly confidential financial and personal data. It isn't recycled, archived, or scanned; it's destroyed and the retention period ends there.

Our systems
What security measures protect the systems behind ACH payments?+

Security is built into the system at every layer, not added on afterward:

  • Network: Our payment platform is protected by a firewall with strict, limited port access — only what's needed for the service to function is open to the outside world.
  • Transport: All connections are encrypted using modern TLS protocols with strong, current cipher configurations, so information you enter can't be read in transit.
  • Server hardening: The systems that process payment requests run on a hardened server configuration with active application-layer protections against common web attacks.
  • Data minimization: Rather than trying to perfectly secure a database of stored payment data, we avoid creating one — form data is verified, transmitted, and not retained electronically.

We deliberately keep some infrastructure specifics off this page — publishing exact configurations publicly can help attackers as much as it helps reassure customers. If you'd like more detail (for example, for your own vendor security review), contact us directly and we're glad to share more under appropriate terms.

Who can access my payment data internally?+

Access is limited by design rather than by policy alone. Because payment data isn't stored electronically, there's no internal database for staff to browse. The single daily physical record is kept in a locked cabinet with restricted, need-to-know access, consistent with our regulatory retention obligations.

What should I do if I notice something suspicious?+

If you receive a payment request you didn't expect, notice unusual activity, or aren't sure whether a communication is really from us, stop and contact us directly using the information below before taking any action.