Security & Trust

Invogi handles supplier bank details and invoice data for EU mid-market finance teams. Here's what we do to protect it, and who we share it with.

Controls

Encryption

TLS 1.2+ in transit everywhere; encryption at rest via our managed infrastructure providers.

Tenant isolation

Every record is scoped to your organization; authorization is enforced centrally, not per-query.

API key hashing

Keys are hashed at rest and shown once at creation. We never log the raw key.

Audit trail

Role changes, key lifecycle, uploads, policy changes, and finding reviews are logged and append-only.

Role-based access

Four roles — Owner, Admin, Analyst, Viewer — with bank account visibility restricted by role.

File safety

Stored-byte MIME validation, size/page limits, defensive XML/PDF parsing, and SHA-256 fingerprinting on every upload.

Sub-processors

Who else touches your data

ProviderPurpose
CloudflareObject storage (R2), edge compute (Workers), and opt-in Workers AI document processing
Managed PostgreSQL providerSystem of record for invoice and finding data
Microsoft AzureOpt-in Document Intelligence processing for scanned, image, long, or uncertain documents
ClerkAuthentication and account identity
ResendOrganization invitation email delivery
PaddleSubscription billing and EU VAT — processes payment and billing-contact data, not invoice content

Read the full Data Processing Agreement →

We do not claim SOC2/ISO/GDPR certification unless it's true and current. If you need our sub-processor list or a signed DPA for a security review, contact us.