Legal

Security Measures

Version 1.0 · effective 9 August 2026

This overview is Annex 3 to our data processing agreement. It describes the technical and organisational measures we take under Article 32 GDPR.

We list only measures that are actually in use. At the bottom we state what we do not have.

1. Access security

  • Two-factor authentication is supported and can be made mandatory.
  • Passwords are stored hashed.
  • Role-based access, with rights bound to a company. Users see only data belonging to their own company. This is enforced in the database, not only in the interface.
  • Connection secrets, such as the tokens for Microsoft and Exact Online, are not reachable from the browser.
  • Administrator access to production systems is personal and limited to those who need it.

2. Encryption

  • All connections run over TLS.
  • Storage and backups are encrypted, according to our hosting providers' guarantees.

3. Application security

  • Approval links in email use single-use tokens that expire. Their use is recorded.
  • Incoming integrations and webhooks are verified.
  • We check sender authenticity on incoming invoice email.
  • Input is validated, in both the frontend and the backend.
  • Product analytics and session replay mask all input fields and all displayed text.

4. Continuity and recovery

  • Daily backups to a second provider, separate from the primary hosting.
  • Backups are used only for recovery after an incident.

5. Logging and auditability

  • Audit trail per invoice, from receipt to submission to accounting.
  • AI steps and decisions taken are logged.
  • Error and synchronisation logs.

6. Data minimisation

  • From connected mailboxes we store metadata and the recognised invoice attachments. We do not store message bodies.
  • AI processing runs in the European Union, except for one search function that is not bound to a region. See the subprocessor list.
  • Payment details stay with our payment provider. We receive only status events.

7. Organisational measures

  • Everyone processing personal data under our authority is bound by confidentiality.
  • Wouter Murmans is responsible for security and privacy. The public contact point is [email protected].
  • We review this document and the subprocessor list at least once a year.

8. What we do not have

  • We hold no ISO 27001 or SOC 2 certification.
  • We do not commission periodic external security audits or penetration tests.
  • We have no formally documented secure development process.
  • We have no tested restore procedure for backups.
  • We have no contractual RTO or RPO targets.

9. Reporting a security problem

Found a vulnerability? Send an email to [email protected] with "security" in the subject. We respond as quickly as we can, and we will not take legal action against reporters who disclose responsibly and who do not access, alter or share other people's data.

Questions about this document? [email protected]