Security
Built to be trusted with a ledger
Finance software earns trust by being predictable. These are the controls that make automated posting safe, and the boundaries around your data.
Isolated by organization
Every record carries its organization and every query is scoped to it. One organization cannot see another's documents, vendors, corrections or metrics — that isolation is enforced in the data layer and covered by automated tests.
Your documents are not training data
We do not train models on your invoices. Extractions and reviewer corrections are used to show you your own accuracy over time, and for nothing else.
A human gate you control
Auto-approval is opt-in and threshold-driven. Anything failing an arithmetic check, or with a vendor that is not in your master data, cannot post without a person approving it explicitly.
An auditable trail
Every document keeps its full history: what was extracted, which checks passed, what a reviewer changed, who approved it and what reference came back from your ERP.
Idempotent by design
Pushes carry an idempotency key. A network failure and a retry produce one invoice in your ledger, never two.
Runs where you need it
Hosted by us, or deployed into your own cloud or data centre when policy requires it.

Questions from your security team?
Send them over. We would rather answer a long questionnaire early than surprise anyone later.