Security & Trust
Invogi handles supplier bank details and invoice data for EU mid-market finance teams. Here's what we do to protect it, and who we share it with.
Controls
Encryption
TLS 1.2+ in transit everywhere; encryption at rest via our managed infrastructure providers.
Tenant isolation
Every record is scoped to your organization; authorization is enforced centrally, not per-query.
API key hashing
Keys are hashed at rest and shown once at creation. We never log the raw key.
Audit trail
Role changes, key lifecycle, uploads, policy changes, and finding reviews are logged and append-only.
Role-based access
Four roles — Owner, Admin, Analyst, Viewer — with bank account visibility restricted by role.
File safety
Stored-byte MIME validation, size/page limits, defensive XML/PDF parsing, and SHA-256 fingerprinting on every upload.
Sub-processors
Who else touches your data
| Provider | Purpose |
|---|---|
| Cloudflare | Object storage (R2), edge compute (Workers), and opt-in Workers AI document processing |
| Managed PostgreSQL provider | System of record for invoice and finding data |
| Microsoft Azure | Opt-in Document Intelligence processing for scanned, image, long, or uncertain documents |
| Clerk | Authentication and account identity |
| Resend | Organization invitation email delivery |
| Paddle | Subscription billing and EU VAT — processes payment and billing-contact data, not invoice content |