Skip to content

Trust

Security at Involiqo

Involiqo is designed to protect business, financial and invoice information throughout upload, review and day-to-day use.

Business-scoped access

Customer records are separated by business workspace. Database policies enforce business membership and role-aware permissions, while sensitive service credentials remain on trusted server infrastructure rather than in the browser.

Private invoice handling

Invoice files use private storage and a quarantine workflow. Uploads are checked for allowed file type, name and size, scanned for malware, and promoted to final storage only after a clean result. Direct customer writes to final invoice storage are blocked.

Reviewable AI extraction

AI-assisted extraction is treated as probabilistic, not authoritative. Proposed supplier, total and line-item information is shown for human review, with validation and confidence cues before it becomes an accepted business record.

Auditability and operational controls

  • Important invoice, access and security events are recorded for investigation and accountability.
  • Destructive and administrative actions are limited by role and require additional confirmation.
  • Application errors exposed to users are sanitised to avoid leaking provider or credential details.
  • Production dependencies and access-control policies are covered by automated and live checks.

Your responsibilities

Security is shared. Use a unique password, protect access to your email and devices, assign the minimum role each team member needs, remove access promptly when responsibilities change and review extracted information before accepting it.

Report a security concern

If you believe you have found a vulnerability, please report it privately and give us reasonable time to investigate before public disclosure. Include the affected URL or feature, clear reproduction steps and the impact you observed. Do not access data that is not yours, disrupt the service or use destructive testing.

Use our Contact page for the current reporting route.

This reporting channel does not create a bug-bounty programme or promise payment. We will acknowledge and assess good-faith reports as promptly as practical.

Privacy

For information about personal-data handling, retention and individual rights, read the Privacy Policy.