Verify payment changes outside the inbox.
Business Email Compromise redirects supplier payments by changing bank details over email. ProofRelay is a controlled verification and approval system that reduces that risk — every payment-detail change is verified through a pre-established contact and approved by a second person before money moves.
Holding a suspicious invoice right now? Check it free — no account, nothing leaves your browser

How it works
One controlled path from instruction to payment release
Log the instruction
A supplier asks to change their bank details. Forward the email to your organisation's private ProofRelay address — or log it in ten seconds. Either way, nobody acts on the email itself.
See deterministic risk indicators
Twenty-three transparent rules flag changed destinations, first payments to new suppliers, lookalike sender domains, accounts your organisation already rejected, offshore redirects, urgency and secrecy language — no black boxes.
Verify out-of-band
A different team member calls a trusted contact that existed before the instruction arrived. Numbers inside the email are never used.
Approve with separated duties
A separate approver reviews the verification and approves or rejects. Nobody can verify or approve their own request — the server enforces it.
Release with a reference
Approval issues a payment-release reference bound by a SHA-256 hash to the exact amount, currency and destination. Change any of them and the reference revokes itself.
Keep a tamper-evident record
Every step lands in a hash-chained audit trail with a printable decision record for auditors and insurers.
Built different
Security your team can't accidentally bypass
Every policy check runs on the server in a single transaction. The UI is the easiest way to use ProofRelay — but it is never the enforcement layer.
Who it's for
Anyone who pays suppliers is a target
BEC doesn't need to breach your network — it only needs one convincing email and one busy afternoon.
Pricing
A fraction of one redirected invoice
Every plan includes the full verification workflow — the tiers scale with your team, not with your security.
Running controls for client businesses? During early access, every client organisation is free — no client limit, no payment details.
The Free plan is free forever. Paid plans are also free during early access — no payment details required.
FAQ
Common questions
Does ProofRelay move money or connect to my bank?
No. ProofRelay never touches funds and has no banking integration. It controls the decision — whether a changed payment detail is verified and approved — and issues a release reference your team checks before paying through your normal banking channel.
What stops someone on my team from skipping the checks?
Every rule runs on the server in a single atomic transaction: the requester can never verify or approve their own request, and verification can only use pre-established contacts. The UI is a convenience — it is not the enforcement layer, so there is nothing to click around.
What is a release reference?
On approval, ProofRelay issues a code bound by a SHA-256 hash to the exact amount, currency and destination that were verified. Anyone on your team can validate it before paying — validation recomputes that hash from the live record, so if any material detail changed afterwards the reference is revoked on the spot rather than quietly passing.
What happens when a supplier genuinely changes banks?
That is the exact case ProofRelay is built for. The change is logged, a colleague calls a contact your team established before the request existed, and someone other than the requester approves. A genuine change passes in one phone call; a fraudulent one fails the callback.
What about the first time we pay someone new?
First payments are where much of this fraud actually happens — a fake or hijacked first invoice, with no history to contradict it. When you add a supplier you've never paid, their account details enter as a request to verify, not as something trusted: you establish a contact from an independent source (their contract, the ABN register, their official website — never the invoice itself), a colleague calls, and approval creates the first verified account. Until that completes, the payment-run check flags any batch line paying them.
Is this based on official guidance?
The workflow implements the controls the Australian Cyber Security Centre publishes for preventing business email compromise (cyber.gov.au): an approval process for payment-detail changes and large transfers, verification by calling the sender on a known number — never one from the email — and treating urgency, secrecy, and requests to bypass procedure as red flags. The lookalike-domain detection covers the ACSC's published impersonation patterns, from swapped characters to added words. ProofRelay is not affiliated with or endorsed by the ACSC; it automates the controls they recommend.
Can my supplier check a reference without an account?
Yes. An administrator can generate a public verification link for any live release reference and send it to the supplier — or anyone else who needs assurance. The link shows only the status, organisation and supplier names, amount, and a masked destination. It can be rotated at any time, every check is recorded in the audit trail, and a material change revokes it automatically.
Are the risk indicators AI-based?
No — deliberately. Twenty-three deterministic rules check things like changed destinations, first payments to unknown suppliers, lookalike sender domains (one character away from a domain you trust), accounts previously rejected by your organisation, one account claimed by two different suppliers, destinations moving offshore, and urgency or secrecy language. Every indicator states exactly why it fired, so your team and your auditors can reason about it.
How long does setup take?
Under an hour for most teams: create your organisation, add suppliers with their known-good payment details from your accounting system, and establish trusted contacts. Your next payment-detail change then goes through the verified path.
Is the Free plan actually free?
Yes — free forever, with the complete verification workflow, all 23 risk indicators, and the tamper-evident audit trail for up to five suppliers and three team members. It is the full product, not a trial. You outgrow it by adding suppliers, not by hitting a paywall on security features.
We're a bookkeeping practice — do we pay per client?
Not during early access: add every client organisation free, with no payment details and no client limit. Each client keeps its own suppliers, policies and tamper-evident audit trail, and your team sees one portfolio view across all of them, ranked by what needs attention. When billing arrives it will land on the Firm tier first, and practices already on board will hear about pricing before it applies to them.
What ProofRelay is — and is not
ProofRelay is a controlled verification and approval system that reduces the risk of BEC-related payment fraud. It enforces your policy on the server: separation of duties, independent callback verification through pre-established contacts, and tamper-evident decision records.
It does not move money, connect to banking systems, verify legal ownership of bank accounts, or guarantee that an instruction is authentic. A legitimate supplier mailbox may itself be compromised — which is exactly why verification happens outside the inbox. ProofRelay complements, and never replaces, email security, phishing-resistant MFA, accounting controls and your bank's own checks.
Start verifying payment changes today
Set up your organisation, add your suppliers and trusted contacts, and your next payment-detail change goes through a verified path.
Create your organisation
